MS.Windows.cng.sys.Security.Bypass
Description
This indicates an attack attempt to exploit an Information Disclosure vulnerability in Microsoft Windows Kernel.
The vulnerability is due to an error when the vulnerable software handles malicious calls to IOCTL. A remote attacker may be able to exploit this to gain sensitive information from vulnerable systems.
Affected Products
Windows 8 and Windows 8.1
Windows Server 2012 and Windows Server 2012 R2
Windows RT and Windows RT 8.1
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
http://technet.microsoft.com/security/bulletin/MS15-052
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |