CVE-2016-0167highunder attackransomware

CVE-2016-0167

Published · Updated

51Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and 1 threat group(s) use it.

ssvc Actcvss 7.8epss 5.7%
from disclosure to weapon
Published on NVDApr 12
CISA KEV+2031d
exploitation probability
5.7%top 7% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 group(s)
Who exploits it — 1

Groups known to exploit this vulnerability (MITRE ATT&CK attribution).

APT / StateFIN8 MITRE ATT&CK
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

A vulnerability in Windows kernel-mode driver allows a local user to run a specially crafted application to gain administrative privileges on their computer. This is a serious flaw because it lets someone with regular access escalate to full system control.

Technical detail

Local privilege escalation vulnerability in the Win32k kernel-mode driver affecting multiple Windows versions. An authenticated local attacker can exploit this via a malicious application to elevate privileges to SYSTEM level without requiring special preconditions beyond local access.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0165.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a