ID:434 - Exploit for Privilege escalation in Windows - CVE-2016-7188

 
Main Vulnerability Database Exploits ID:434 - Exploit for Privilege escalation in Windows - CVE-2016-7188

ID:434 - Exploit for Privilege escalation in Windows - CVE-2016-7188

Published: March 18, 2020


Vulnerability identifier: #VU979
Vulnerability risk: High
CVE-ID: CVE-2016-7188
CWE-ID: CWE-20
Exploitation vector: Local access
Vulnerable software:
Windows

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to obtain elevated privileges on the target system.
The weakness exists due to insufficient sanitization of user-supplied input by the Windows Diagnostics Hub Standard Collector Service. By executing a crafted application and causing unsecure library loading attackers can obtain root privileges on the affected system that allows them to execute arbitrary code with system privileges.
Succesful exploitation of the vulnerability may result in complete vulnerable system compromise.

Remediation

Cybersecurity Help is currently unaware of any official patch addressing the vulnerability.