ZeroHour

CVE-2016-0167

KEV ransomwaremass

Win32k Local Privilege Escalation in Microsoft Windows (Vista through 10 1511)

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2016-0167 is an elevation-of-privilege flaw in the Windows kernel-mode Win32k driver affecting Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1511, and Windows Server 2008, 2008 R2, 2012 and 2012 R2. A local attacker must get a user to run a crafted application (the CVSS vector requires user interaction), which then abuses the Win32k bug to break out of user context into the kernel. Successful exploitation grants full local privileges with high impact on confidentiality, integrity and availability, and is commonly chained with other malware or ransomware for complete system compromise. Any unpatched machine on those operating system versions is affected; the April 2016 Microsoft security updates (MS16-034) and all later cumulative updates fix it, so residual exposure is concentrated in legacy estates that never applied the patch. Exploitation is confirmed in the wild: CISA added the CVE to the KEV catalog on 2021-11-03 with known ransomware use (EPSS 5.7% 30-day probability, 93rd percentile), and related coverage of the FireEye tool-theft disclosures warned that millions of unpatched devices could be hacked using exploits targeting this flaw class.

What to do: Apply the April 2016 Microsoft security updates (MS16-034) or any later cumulative/monthly rollup to every affected Windows Vista, 7, 8.1, RT 8.1, 10 (1507/1511), Server 2008/2008 R2 and 2012/2012 R2 system, and verify the Win32k kernel driver is at the patched level. Since these operating systems are past end of support, prioritize migration to supported Windows versions or enroll legacy servers in extended security updates. Because this is a KEV entry with known ransomware use, treat any unpatched legacy host as at risk and hunt for local privilege-escalation activity chained with malware or ransomware.

Affected
Microsoft Windows VistaSP2
Microsoft Windows 7SP1
Microsoft Windows 8.1all editions
Microsoft Windows RT 8.1all editions
Microsoft Windows 101507 (RTM/Gold) and 1511
Microsoft Windows Server 2008SP2 and R2 SP1
Microsoft Windows Server 2012RTM (Gold) and R2
Estimated exposure
masshundreds of millions of devices in the affected Windows install base at disclosure (order of 10^8); millions of still-unpatched legacy Windows 7/8.1 and Server… — Windows 7 and 8.1 dominated a global Windows PC base exceeding one billion devices when the April 2016 fix shipped, and legacy Windows 7/8.1/10 1507-1511 and Server 2008/2012 deployments that never upgraded or applied later updates remain…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0165.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows vista
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news