CVE-2016-0040
KEV PoC massLocal Privilege Escalation in Microsoft Windows Kernel (Win32k)
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2016-0040 is an elevation-of-privilege flaw in the Microsoft Windows kernel's kernel-mode drivers (win32k) that a local user can exploit by running a specially crafted application. Successful exploitation executes code in kernel mode, effectively granting the attacker SYSTEM-level control of the host — typically used to climb from an initial foothold to full system compromise. The flaw is not remotely exploitable on its own; it requires pre-existing local code execution, so it is usually chained after an RCE, a malware dropper, or malicious user activity. At disclosure it affected all mainstream Windows releases of the era — Windows Vista/Server 2008 through Windows 10 (1511 and earlier)/Server 2012 R2 — patched via Microsoft's January 2016 kernel-mode driver bulletin (MS16-005) and included in all later cumulative updates, so the realistic residual exposure is legacy Windows estates that never applied those patches (end-of-support Windows 7, Server 2008/2012). CISA added it to the KEV catalog on 2022-03-28, confirming in-the-wild exploitation; it also ranks in the 98th EPSS percentile (24.5% chance of exploitation activity in 30 days), though no public PoC is catalogued and ransomware use is unknown.
What to do: Verify that every Windows host has Microsoft's January 2016 kernel-mode driver update (MS16-005) or a later cumulative update installed — any modern Windows 10/11 patch level includes the fix, so prioritize legacy Windows 7, Server 2008/2008 R2, and Server 2012/2012 R2 systems, including ESU-enrolled and fully unpatched machines. Because exploitation requires local code execution, patch first where untrusted users run applications or where RDP/terminal services are exposed. CISA's required action is to apply updates per vendor instructions; where patching is not possible, restrict local logon rights and limit untrusted users on affected hosts.
| Microsoft Windows | Mainstream Windows releases at time of disclosure: Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and 20 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 7, windows server 2008, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H