Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2016-7216Sensitive Information Exposure in Microsoft Windows Server 2008

Severity
5.5MEDIUMNVD
EPSS
2.8%
top 13.96%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 10
Latest updateMay 14

Description

The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

🔴Vulnerability Details

1
GHSA
GHSA-vx2m-r4vc-jvvr: The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users2022-05-14

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows Kernel - Registry Hive Loading 'nt!RtlEqualSid' Out-of-Bounds Read (MS16-138)2016-11-15

📋Vendor Advisories

1
Microsoft
Windows Elevation of Privilege Vulnerability2016-11-08

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - November 20162016-11-08
Talos
Microsoft Patch Tuesday - November 20162016-11-08