Executive brief
A privilege escalation vulnerability exists in the Microsoft Windows kernel-mode driver (Win32k). Local users can exploit this flaw via a crafted application to gain elevated system privileges.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 Gold
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT 8.1 Gold
- Microsoft Windows 10 Gold, 1511
Timeline
- 2016-04-12: patched: Microsoft released security bulletin MS16-039 to address this vulnerability.
- 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: NVD publication date.