ZeroHour

CVE-2016-0165

KEVmass

Local Privilege Escalation in Microsoft Win32k Kernel Driver

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
14%p96
Published
()
KEV added
AI analysis

CVE-2016-0165 is a Win32k elevation-of-privilege flaw in the Windows kernel-mode driver, affecting Windows Vista SP2 through Windows 10 version 1511 and the corresponding Server editions. An attacker must already be able to run a crafted application locally on the affected machine, at which point the flaw can be triggered to escape the user context. Successful exploitation grants the attacker SYSTEM/kernel-level privileges, providing complete confidentiality, integrity, and availability impact on the host. Any organization running the listed Windows versions is exposed, especially servers and workstations used for shared access. The flaw has been exploited in the wild: it was used as a zero-day in targeted attacks attributed to the FruityArmor APT, it carries a 13.8% EPSS probability of exploitation within 30 days, and CISA added it to the KEV on 2023-06-22, requiring federal agencies to apply vendor updates.

What to do: Apply the vendor security updates for CVE-2016-0165 per Microsoft's instructions on all affected Windows Vista, Server 2008/2012, Windows 7, 8.1, RT 8.1, and Windows 10 1507/1511 systems, prioritizing KEV-driven remediation. Because this is a local privilege escalation, limit interactive and remote logon rights to untrusted users on hosts that cannot be patched immediately, and ensure endpoint monitoring watches for the FruityArmor-style targeted attack activity. Systems such as Vista, Windows 7, and Windows 10 1507/1511 that are past mainstream support should be upgraded to a supported OS release where possible.

Affected
microsoft windows vistaSP2
microsoft windows 7SP1
microsoft windows 8.1all supported at time of disclosure
microsoft windows rt 8.1all supported at time of disclosure
microsoft windows 10 15071507 (RTM/Gold)
microsoft windows 10 15111511
microsoft windows server 2008SP2; Server 2008 R2 SP1
microsoft windows server 2012Server 2012 (Gold); Server 2012 R2
Estimated exposure
masshundreds of millions of Windows PCs and servers (the affected OS versions spanned essentially the entire Windows install base at disclosure) — The flaw affects the shared Win32k component in every listed desktop and server OS from Vista through Windows 10 1511, which together accounted for the overwhelming majority of the Windows installed base when patched, with Windows 10 alone…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows vista
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news