CVE-2016-7222Microsoft Windows 10 vulnerability

CWE-254CWE-2645 documents4 sources
Severity
7.8HIGHNVD
EPSS
1.1%
top 22.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 14

Description

Task Scheduler in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to gain privileges via a crafted UNC pathname in a task, aka "Task Scheduler Elevation of Privilege Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

🔴Vulnerability Details

1
GHSA
GHSA-w3p9-g499-4448: Task Scheduler in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to gain privileges via a crafted UNC pathname i2022-05-14

📋Vendor Advisories

1
Microsoft
Task Scheduler Elevation of Privilege Vulnerability2016-11-08

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - November 20162016-11-08
Talos
Microsoft Patch Tuesday - November 20162016-11-08