⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2022-04-05.

CVE-2016-3309Microsoft Windows 10 vulnerability

CWE-26421 documents11 sources
Severity
7.8HIGHNVD
EPSS
46.3%
top 2.34%
CISA KEV
KEVRansomware
Added 2022-03-15
Due 2022-04-05
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedAug 9
KEV addedMar 15
KEV dueApr 5
Latest updateJun 11
CISA Required Action: Apply updates per vendor instructions.

Description

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages14 packages

Patches

🔴Vulnerability Details

5
GHSA
GHSA-vw6r-qqvc-7vxx: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 82022-05-14
GHSA
GHSA-26jv-vj2h-8566: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 82022-05-14
GHSA
GHSA-fgfw-9qp4-g6xg: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 82022-05-14
GHSA
GHSA-7cmx-3w9q-4v5g: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 82022-05-14
VulnCheck
Microsoft Windows Kernel Privilege Escalation Vulnerability2016

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows 10 RS2 (x64) - 'win32kfull!bFill' Pool Overflow2017-10-06

📋Vendor Advisories

2
CISA
Microsoft Windows Kernel Privilege Escalation Vulnerability2022-03-15
Microsoft
Windows Kernel Elevation of Privilege Vulnerability2016-08-09

🕵️Threat Intelligence

9
Tenable
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs2024-06-11
Bleepingcomputer
Privilege elevation exploits used in over 50% of insider attacks2023-12-08
Tenable
Microsoft’s May 2023 Patch Tuesday Addresses 38 CVEs (CVE-2023-29336)2023-05-09
Tenable
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help2022-03-24
Tenable
Microsoft’s October 2021 Patch Tuesday Addresses 74 CVEs (CVE-2021-40449)2021-10-12