Junglewise Threat Intelligence

CVE-2016-0040: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVE-2016-0040 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

The kernel in Microsoft Windows allows local users to gain elevated privileges via a crafted application. This vulnerability affects legacy versions of Windows including Vista, Server 2008, and Windows 7.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1

Timeline

  • 2016-02-10: disclosed: NVD Published Date
  • 2016-02-10: patched: Microsoft released security bulletin MS16-014
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats