CVE-2016-7271Microsoft Windows 10 vulnerability

CWE-2645 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 69.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateMay 14

Description

The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to bypass the virtual trust level (VTL) protection mechanism via a crafted application, aka "Secure Kernel Mode Elevation of Privilege Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

🔴Vulnerability Details

1
GHSA
GHSA-cgfg-gp9v-cc74: The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to bypass the virtual tr2022-05-14

📋Vendor Advisories

1
Microsoft
Windows Elevation of Privilege Vulnerability2016-12-13

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - December 20162016-12-13
Talos
Microsoft Patch Tuesday - December 20162016-12-13