CVE-2016-3346
published 2016-09-14CVE-2016-3346: Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafted DLL, aka…
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
1.36%
68.9th percentile
Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafted DLL, aka "Windows Permissions Enforcement Elevation of Privilege Vulnerability."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jpv2-6cgw-x26x: Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafted
ghsa_unreviewed·2022-05-14
CVE-2016-3346 [HIGH] GHSA-jpv2-6cgw-x26x: Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafted
Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafted DLL, aka "Windows Permissions Enforcement Elevation of Privilege Vulnerability."
Microsoft
Windows Permissions Enforcement Elevation of Privilege Vulnerability
vendor_msrc·2016-09-13·CVSS 7.8
CVE-2016-3346 [HIGH] Windows Permissions Enforcement Elevation of Privilege Vulnerability
Windows Permissions Enforcement Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that Windows enforces permissions if an attacker loads a specially crafted DLL. A locally authenticated attacker who successfully exploited this vulnerability could run arbitrary code as a system administrator. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit the vulnerability, an attacker would need to create and implement a malicious DLL and already be able to execute code on the target system.
The security update addresses the vulnerability by correcting how Windows enforces permissions.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Require
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/92846http://www.securitytracker.com/id/1036798https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-110http://www.securityfocus.com/bid/92846http://www.securitytracker.com/id/1036798https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-110
2016-09-14
Published