CVE-2016-3302: Microsoft Windows 10

Medium severity, CVSS 6.3. EPSS: 2.4% chance of exploitation in the next 30 days.

Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code via a (1) crafted Wi-Fi access point or (2) crafted mobile-broadband device, aka "Windows Lock Screen Elevation of Privilege Vulnerability."

Affected products

  • Microsoft Windows 10: affected versions not specified; version 1511 only; version 1607 only
  • Microsoft Windows 8.1: affected versions not specified
  • Microsoft Windows Rt 8.1: affected versions not specified
  • Microsoft Windows Server 2012: version r2 only

Published 2016-09-14. Last modified 2026-06-17.