vulnerability

Microsoft Windows: CVE-2016-3352: Windows Information Disclosure Vulnerability

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
Sep 14, 2016
Added
Jun 10, 2024
Modified
Oct 14, 2025

Description

Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords via a brute-force attack on NTLM password hashes, aka "Microsoft Information Disclosure Vulnerability."

Solutions

microsoft-windows-windows_10-1507-kb3185611microsoft-windows-windows_10-1511-kb3185614microsoft-windows-windows_10-1607-kb3189866
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.