Executive brief
The Win32k kernel-mode driver in multiple Microsoft Windows versions fails to properly handle objects in memory. This vulnerability allows a local attacker to gain elevated privileges via a crafted application, potentially executing code in kernel mode.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 Gold
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT 8.1 Gold
- Microsoft Windows 10 Gold, 1511, 1607
- Microsoft Windows Server 2016 Gold
Timeline
- 2016-10-31: disclosed: Google disclosed the vulnerability after 7 days of notification to Microsoft.
- 2016-11-08: patched: Microsoft released security bulletin MS16-135.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- exploited: Reported as exploited in the wild by multiple sources including Trend Micro and Google.