CVE-2016-0051
70Vexday Risk Score
Patch now. It exploitation observed by VulnCheck, has a working public exploit and 1 threat group(s) use it.
ssvc Actepss 23%
from disclosure to weapon0 days
Published on NVDFeb 10
1st PoCFeb 9
metasploitFeb 9
VulnCheck+1120d
exploitation probability
23%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 group(s)12 public exploit(s)
Who exploits it — 1
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "WebDAV Elevation of Privilege Vulnerability."
Affected products
n/a · n/apublic PoCs found — 12✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39788exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39432exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/40085githubgithub.com/koczkatamas/CVE-2016-0051★ 323githubgithub.com/hexx0r/CVE-2016-0051★ 41githubgithub.com/ganrann/CVE-2016-0051★ 0vulncheckvulncheck.com/xdb/3c19d2cac82dunverifiedcve_referencewww.exploit-db.com/exploits/40085/unverifiedcve_referencewww.exploit-db.com/exploits/39432/unverifiedvulncheckvulncheck.com/xdb/0661e358e96aunverifiedvulncheckvulncheck.com/xdb/47c8692bb391unverifiedcve_referencewww.exploit-db.com/exploits/39788/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.