CVE-2016-7255
KEV ransomware PoC ×5massWin32k Local Privilege Escalation in Windows Vista Through Windows 10 and Server 2016
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2016-7255 is an elevation-of-privilege flaw in the Windows kernel-mode drivers (win32k), affecting Windows Vista SP2 through Windows 10 1607 and the corresponding Windows Server releases. A local attacker who can run a crafted application can leverage the bug — public exploits target the win32k NtSetWindowLongPtr code path — to execute code with elevated kernel privileges. Successful exploitation yields SYSTEM-level privileges, typically used to escape a restricted context or to chain with a separate code-execution bug for full system compromise, including ransomware deployment. Anyone running the affected Windows versions is exposed; the flaw was a zero-day actively exploited at the time of its November 2016 disclosure, with reporting tying use to the Sofacy/'Pawn Storm' APT and Google warning of active exploitation. It was added to CISA KEV on 2021-11-03 with known ransomware use, and EPSS currently puts the 30-day exploitation probability at 81%, so defenders should treat it as actively targeted.
What to do: Apply Microsoft's security update for CVE-2016-7255 (issued in the November 2016 Patch Tuesday cycle, bulletin MS16-135); on Windows 10 1507/1511/1607 this arrives via the corresponding monthly cumulative update. Prioritize patching internet-reachable servers and any system where unprivileged users can run code, since the flaw is used in the wild for post-exploitation privilege escalation (including ransomware chains per CISA KEV). After patching, hunt for suspicious local-to-SYSTEM activity around the disclosure window on legacy Windows Vista/2008/7/2012 estate that may still be running unpatched builds.
| microsoft Windows Vista | SP2 |
| microsoft Windows Server 2008 | SP2 and R2 SP1 |
| microsoft Windows 7 | SP1 |
| microsoft Windows 8.1 | all supported builds at disclosure (no SP restriction listed) |
| microsoft Windows RT 8.1 | all supported builds at disclosure |
| microsoft Windows 10 | 1507 (Gold), 1511, and 1607 |
| microsoft Windows Server 2012 | Gold and R2 |
| microsoft Windows Server 2016 | Gold (initial release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H