CVE-2016-3352: Microsoft Windows 10

High severity, CVSS 8.8. EPSS: 20.8% chance of exploitation in the next 30 days.

Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords via a brute-force attack on NTLM password hashes, aka "Microsoft Information Disclosure Vulnerability."

Affected products

  • Microsoft Windows 10: affected versions not specified; version 1511 only; version 1607 only
  • Microsoft Windows 8.1: any version
  • Microsoft Windows Rt 8.1: any version

Published 2016-09-14. Last modified 2026-06-17.