CVE-2016-3309
KEV ransomwaremassPrivilege Escalation in Microsoft Windows Kernel (CVE-2016-3309)
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2016-3309 is a privilege escalation vulnerability in the Microsoft Windows kernel caused by improper handling of objects in memory. Triggering it typically requires getting crafted code to run on the system (the usual pattern for kernel EoP flaws), after which the kernel mishandles the objects and the attacker can execute arbitrary code in kernel mode. Successful exploitation grants full system-level privileges, letting an attacker disable security tooling, steal credentials, and deploy payloads such as ransomware. CISA lists the affected product broadly as Microsoft Windows, with older and legacy Windows builds being the most likely remaining targets for this 2016-era flaw. Exploitation is confirmed in the wild: the flaw was added to the CISA KEV catalog on 2022-03-15 with known ransomware use, and EPSS assigns a 20.6% probability of exploitation in the next 30 days (97th percentile).
What to do: Apply Microsoft's kernel-mode security updates per vendor instructions on all Windows systems, prioritizing legacy/out-of-support builds where this flaw is most likely to remain unpatched. Since the bug is KEV-listed with known ransomware use, verify patch deployment fleet-wide and inventory any Windows hosts that can no longer receive updates, isolating them or applying compensating controls. There is no public PoC, but treat unpatched Windows endpoints with local user or execution access as high priority for remediation.
| Microsoft Windows | Affected per CISA as 'Microsoft Windows'; no specific version ranges are given in the source data — consult Microsoft's original kernel-mode security update for |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H