CVE-2016-0009Microsoft Windows 10 vulnerability

CWE-26410 documents8 sources
Severity
8.8HIGHNVD
EPSS
24.6%
top 3.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 14

Description

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via unspecified vectors, aka "Win32k Remote Code Execution Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

1
GHSA
GHSA-w64j-mh96-gx5j: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitra2022-05-14

💥Exploits & PoCs

1
Exploit-DB
Kamailio 4.3.4 - Heap Buffer Overflow2016-03-30

📋Vendor Advisories

2
VMware
VMware vCenter Server updates address an important reflected cross-site scripting issue2016-06-14
Microsoft
CVE-2016-0009: Impact: Remote Code Execution Exploit Status: Publicly Disclosed:Yes;Exploited:No2016-01-12

🕵️Threat Intelligence

4
Talos
Microsoft Patch Tuesday - January 20162016-01-12
Qualys
Update: Patch Tuesday January 2016 | Qualys2016-01-12
Qualys
Update: Patch Tuesday January 2016 | Qualys2016-01-12
Talos
Microsoft Patch Tuesday - January 20162016-01-12

📐Framework References

1
OWASP
Mastg Tool 0009