CVE-2016-0165
KEVmassLocal Privilege Escalation in Microsoft Win32k Kernel Driver
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2016-0165 is a Win32k elevation-of-privilege flaw in the Windows kernel-mode driver, affecting Windows Vista SP2 through Windows 10 version 1511 and the corresponding Server editions. An attacker must already be able to run a crafted application locally on the affected machine, at which point the flaw can be triggered to escape the user context. Successful exploitation grants the attacker SYSTEM/kernel-level privileges, providing complete confidentiality, integrity, and availability impact on the host. Any organization running the listed Windows versions is exposed, especially servers and workstations used for shared access. The flaw has been exploited in the wild: it was used as a zero-day in targeted attacks attributed to the FruityArmor APT, it carries a 13.8% EPSS probability of exploitation within 30 days, and CISA added it to the KEV on 2023-06-22, requiring federal agencies to apply vendor updates.
What to do: Apply the vendor security updates for CVE-2016-0165 per Microsoft's instructions on all affected Windows Vista, Server 2008/2012, Windows 7, 8.1, RT 8.1, and Windows 10 1507/1511 systems, prioritizing KEV-driven remediation. Because this is a local privilege escalation, limit interactive and remote logon rights to untrusted users on hosts that cannot be patched immediately, and ensure endpoint monitoring watches for the FruityArmor-style targeted attack activity. Systems such as Vista, Windows 7, and Windows 10 1507/1511 that are past mainstream support should be upgraded to a supported OS release where possible.
| microsoft windows vista | SP2 |
| microsoft windows 7 | SP1 |
| microsoft windows 8.1 | all supported at time of disclosure |
| microsoft windows rt 8.1 | all supported at time of disclosure |
| microsoft windows 10 1507 | 1507 (RTM/Gold) |
| microsoft windows 10 1511 | 1511 |
| microsoft windows server 2008 | SP2; Server 2008 R2 SP1 |
| microsoft windows server 2012 | Server 2012 (Gold); Server 2012 R2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H