CVE-2010-0232
KEVmassLocal Privilege Escalation in Microsoft Windows Kernel (32-bit x86, 16-bit apps)
CISA: Microsoft Windows Kernel Exception Handler Vulnerability
CVE-2010-0232 is a local privilege escalation flaw in the Microsoft Windows kernel: on 32-bit x86 platforms, the kernel does not properly validate certain BIOS calls made when 16-bit application support is enabled. A local attacker triggers the flaw by running a malicious 16-bit application on an affected 32-bit Windows system, causing the kernel to execute attacker-controlled code in kernel mode. Successful exploitation grants full elevated (kernel/SYSTEM-level) privileges, typically used as a post-compromise step after an attacker has already obtained local access. Any deployment running 32-bit x86 Windows with access to 16-bit applications enabled is affected, per CISA's listing of 'Microsoft Windows' (specific version ranges are not provided in the source data). The vulnerability was added to the CISA KEV catalog on 2022-03-03, confirming in-the-wild exploitation (ransomware use unknown), and its EPSS of 29.3% (98th percentile) indicates a high likelihood of exploitation over the next 30 days; no public PoC is known per the source data.
What to do: Apply Microsoft updates per vendor instructions (this CVE was addressed in Microsoft Security Bulletin MS10-021) on all 32-bit x86 Windows systems and verify remediation, per the CISA KEV required action. As an interim mitigation, disable access to 16-bit applications (e.g., via the 'Prevent access to 16-bit applications' policy) and restrict untrusted local logons on affected systems. Prioritize hosts where untrusted users can execute 16-bit programs.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Windows
- Weakness
- CWE-264