ID:432 - Exploit for Privilege escalation in Microsoft products - CVE-2016-7182

 
Main Vulnerability Database Exploits ID:432 - Exploit for Privilege escalation in Microsoft products - CVE-2016-7182

ID:432 - Exploit for Privilege escalation in Microsoft products - CVE-2016-7182

Published: March 18, 2020


Vulnerability identifier: #VU975
Vulnerability risk: Medium
CVE-ID: CVE-2016-7182
CWE-ID: CWE-119
Exploitation vector: Local access
Vulnerable software:
Microsoft Office
Windows
Windows Server
Word Viewer
Microsoft Lync
Lync Attendee
Microsoft Live Meeting

Link to public exploit:


Vulnerability description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to boundary error in the Microsoft Windows kernel-mode driver (Win32k). By running a malicious program on the affected system attackers can execute arbitrary code with SYSTEM privileges.

Successful exploitation of the vulnerability may result in a complete system compromise.


Remediation

Install update from vendor's website.