Netlogon privilege escalation in Microsoft products - CVE-2016-3300
Published: August 10, 2016 / Updated: February 2, 2017
Windows
Windows RT
Windows Server
Detailed vulnerability description
The vulnerability allows a local user gain elevated privileges on vulnerable system.
The vulnerability exists due to Windows Netlogon service incorrectly handles secure communication to a domain controller. A local attacker can run arbitrary code on the vulnerable system with elevated privileges.
Successful exploitation of this vulnerability will allow a local user to elevate privileges on the system, joined to Windows Server 2012 or Windows Server 2012 R2 domain controller.