Executive brief
A privilege escalation vulnerability in the Microsoft Windows kernel-mode driver (Win32k) occurs when the kernel fails to properly handle objects in memory. Local attackers can exploit this via a crafted application to execute arbitrary code in kernel mode and gain elevated privileges.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 Gold
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT 8.1 Gold
- Microsoft Windows 10 Gold, 1511, 1607
Timeline
- 2016-08-09: patched: Microsoft released security bulletin MS16-098 to address this issue.
- 2022-03-15: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2022-03-15: disclosed: NVD publication date.