ZeroHour

CVE-2016-7255

KEV ransomware PoC ×5mass

Win32k Local Privilege Escalation in Windows Vista Through Windows 10 and Server 2016

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
81%p100
Published
()
KEV added
AI analysis

CVE-2016-7255 is an elevation-of-privilege flaw in the Windows kernel-mode drivers (win32k), affecting Windows Vista SP2 through Windows 10 1607 and the corresponding Windows Server releases. A local attacker who can run a crafted application can leverage the bug — public exploits target the win32k NtSetWindowLongPtr code path — to execute code with elevated kernel privileges. Successful exploitation yields SYSTEM-level privileges, typically used to escape a restricted context or to chain with a separate code-execution bug for full system compromise, including ransomware deployment. Anyone running the affected Windows versions is exposed; the flaw was a zero-day actively exploited at the time of its November 2016 disclosure, with reporting tying use to the Sofacy/'Pawn Storm' APT and Google warning of active exploitation. It was added to CISA KEV on 2021-11-03 with known ransomware use, and EPSS currently puts the 30-day exploitation probability at 81%, so defenders should treat it as actively targeted.

What to do: Apply Microsoft's security update for CVE-2016-7255 (issued in the November 2016 Patch Tuesday cycle, bulletin MS16-135); on Windows 10 1507/1511/1607 this arrives via the corresponding monthly cumulative update. Prioritize patching internet-reachable servers and any system where unprivileged users can run code, since the flaw is used in the wild for post-exploitation privilege escalation (including ransomware chains per CISA KEV). After patching, hunt for suspicious local-to-SYSTEM activity around the disclosure window on legacy Windows Vista/2008/7/2012 estate that may still be running unpatched builds.

Affected
microsoft Windows VistaSP2
microsoft Windows Server 2008SP2 and R2 SP1
microsoft Windows 7SP1
microsoft Windows 8.1all supported builds at disclosure (no SP restriction listed)
microsoft Windows RT 8.1all supported builds at disclosure
microsoft Windows 101507 (Gold), 1511, and 1607
microsoft Windows Server 2012Gold and R2
microsoft Windows Server 2016Gold (initial release)
Estimated exposure
masshundreds of millions of Windows PCs and servers (the listed versions dominated the global installed base at disclosure) — Estimated from OS market share at the time: the affected versions — Windows 7 SP1, 8.1, 10 1507–1607, and Server 2008/2012/2016 — together made up the overwhelming majority of Windows desktop and server deployments (order of hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows vista
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news