ZeroHour

CVE-2016-3309

KEV ransomwaremass

Privilege Escalation in Microsoft Windows Kernel (CVE-2016-3309)

CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
21%p97
Published
()
KEV added
AI analysis

CVE-2016-3309 is a privilege escalation vulnerability in the Microsoft Windows kernel caused by improper handling of objects in memory. Triggering it typically requires getting crafted code to run on the system (the usual pattern for kernel EoP flaws), after which the kernel mishandles the objects and the attacker can execute arbitrary code in kernel mode. Successful exploitation grants full system-level privileges, letting an attacker disable security tooling, steal credentials, and deploy payloads such as ransomware. CISA lists the affected product broadly as Microsoft Windows, with older and legacy Windows builds being the most likely remaining targets for this 2016-era flaw. Exploitation is confirmed in the wild: the flaw was added to the CISA KEV catalog on 2022-03-15 with known ransomware use, and EPSS assigns a 20.6% probability of exploitation in the next 30 days (97th percentile).

What to do: Apply Microsoft's kernel-mode security updates per vendor instructions on all Windows systems, prioritizing legacy/out-of-support builds where this flaw is most likely to remain unpatched. Since the bug is KEV-listed with known ransomware use, verify patch deployment fleet-wide and inventory any Windows hosts that can no longer receive updates, isolating them or applying compensating controls. There is no public PoC, but treat unpatched Windows endpoints with local user or execution access as high priority for remediation.

Affected
Microsoft WindowsAffected per CISA as 'Microsoft Windows'; no specific version ranges are given in the source data — consult Microsoft's original kernel-mode security update for
Estimated exposure
masswell over 1,000,000 Windows installations broadly in scope (Windows runs on hundreds of millions of devices), with an unquantified but likely large tail of… — Windows holds roughly 70% of desktop OS market share (on the order of a billion devices), and continued ransomware exploitation of this 2016-era kernel bug implies a substantial population of unpatched legacy systems, though the exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows vista
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news