ZeroHour

CVE-2016-0040

KEV PoC mass

Local Privilege Escalation in Microsoft Windows Kernel (Win32k)

CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
24%p98
Published
()
KEV added
AI analysis

CVE-2016-0040 is an elevation-of-privilege flaw in the Microsoft Windows kernel's kernel-mode drivers (win32k) that a local user can exploit by running a specially crafted application. Successful exploitation executes code in kernel mode, effectively granting the attacker SYSTEM-level control of the host — typically used to climb from an initial foothold to full system compromise. The flaw is not remotely exploitable on its own; it requires pre-existing local code execution, so it is usually chained after an RCE, a malware dropper, or malicious user activity. At disclosure it affected all mainstream Windows releases of the era — Windows Vista/Server 2008 through Windows 10 (1511 and earlier)/Server 2012 R2 — patched via Microsoft's January 2016 kernel-mode driver bulletin (MS16-005) and included in all later cumulative updates, so the realistic residual exposure is legacy Windows estates that never applied those patches (end-of-support Windows 7, Server 2008/2012). CISA added it to the KEV catalog on 2022-03-28, confirming in-the-wild exploitation; it also ranks in the 98th EPSS percentile (24.5% chance of exploitation activity in 30 days), though no public PoC is catalogued and ransomware use is unknown.

What to do: Verify that every Windows host has Microsoft's January 2016 kernel-mode driver update (MS16-005) or a later cumulative update installed — any modern Windows 10/11 patch level includes the fix, so prioritize legacy Windows 7, Server 2008/2008 R2, and Server 2012/2012 R2 systems, including ESU-enrolled and fully unpatched machines. Because exploitation requires local code execution, patch first where untrusted users run applications or where RDP/terminal services are exposed. CISA's required action is to apply updates per vendor instructions; where patching is not possible, restrict local logon rights and limit untrusted users on affected hosts.

Affected
Microsoft WindowsMainstream Windows releases at time of disclosure: Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and 20
Estimated exposure
massApproximately hundreds of millions of Windows devices at the January 2016 patch date (every mainstream release was affected); residual unpatched exposure today… — Every mainstream Windows desktop and server release was affected when the flaw was patched in January 2016, and Windows held roughly 75% desktop share of a billion-plus-device install base; lingering exposure is estimated from deployment…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 7, windows server 2008, windows vista
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news