CVE-2016-0167
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and 1 threat group(s) use it.
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
Apply updates per vendor instructions.
A vulnerability in Windows kernel-mode driver allows a local user to run a specially crafted application to gain administrative privileges on their computer. This is a serious flaw because it lets someone with regular access escalate to full system control.
Local privilege escalation vulnerability in the Win32k kernel-mode driver affecting multiple Windows versions. An authenticated local attacker can exploit this via a malicious application to elevate privileges to SYSTEM level without requiring special preconditions beyond local access.
The full analysis of this CVE is available in Portuguese →