CVE-2016-0167
KEV ransomwaremassWin32k Local Privilege Escalation in Microsoft Windows (Vista through 10 1511)
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2016-0167 is an elevation-of-privilege flaw in the Windows kernel-mode Win32k driver affecting Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1511, and Windows Server 2008, 2008 R2, 2012 and 2012 R2. A local attacker must get a user to run a crafted application (the CVSS vector requires user interaction), which then abuses the Win32k bug to break out of user context into the kernel. Successful exploitation grants full local privileges with high impact on confidentiality, integrity and availability, and is commonly chained with other malware or ransomware for complete system compromise. Any unpatched machine on those operating system versions is affected; the April 2016 Microsoft security updates (MS16-034) and all later cumulative updates fix it, so residual exposure is concentrated in legacy estates that never applied the patch. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2021-11-03 with known ransomware use (EPSS 5.7% 30-day probability, 93rd percentile), and related coverage of the FireEye tool-theft disclosures warned that millions of unpatched devices could be hacked using exploits targeting this flaw class.
What to do: Apply the April 2016 Microsoft security updates (MS16-034) or any later cumulative/monthly rollup to every affected Windows Vista, 7, 8.1, RT 8.1, 10 (1507/1511), Server 2008/2008 R2 and 2012/2012 R2 system, and verify the Win32k kernel driver is at the patched level. Since these operating systems are past end of support, prioritize migration to supported Windows versions or enroll legacy servers in extended security updates. Because this is a KEV entry with known ransomware use, treat any unpatched legacy host as at risk and hunt for local privilege-escalation activity chained with malware or ransomware.
| Microsoft Windows Vista | SP2 |
| Microsoft Windows 7 | SP1 |
| Microsoft Windows 8.1 | all editions |
| Microsoft Windows RT 8.1 | all editions |
| Microsoft Windows 10 | 1507 (RTM/Gold) and 1511 |
| Microsoft Windows Server 2008 | SP2 and R2 SP1 |
| Microsoft Windows Server 2012 | RTM (Gold) and R2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0165.
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H