Junglewise Threat Intelligence

CVE-2016-7255: Microsoft Win32k Privilege Escalation Vulnerability

CVE-2016-7255 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows Rt 8.1, Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Win32K, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

The Win32k kernel-mode driver in multiple Microsoft Windows versions fails to properly handle objects in memory. This vulnerability allows a local attacker to gain elevated privileges via a crafted application, potentially executing code in kernel mode.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 Gold
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT 8.1 Gold
  • Microsoft Windows 10 Gold, 1511, 1607
  • Microsoft Windows Server 2016 Gold

Timeline

  • 2016-10-31: disclosed: Google disclosed the vulnerability after 7 days of notification to Microsoft.
  • 2016-11-08: patched: Microsoft released security bulletin MS16-135.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • exploited: Reported as exploited in the wild by multiple sources including Trend Micro and Google.

Related threats