Buffer overflow in Microsoft Windows and Windows Server - CVE-2016-0040
Published: February 9, 2016 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when processing WMI Receive Notifications. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code on the system with elevated privileges.
Affected software
Windows Server
How to mitigate CVE-2016-0040
Links to Public Exploits and PoC-codes
- Exploit #6372 - Microsoft Windows WMI - Recieve Notification Exploit (Metasploit) (June 17, 2021)
- Exploit #5139 - cve-2016-0040 (Exploiting CVE-2016-0040 uninitialized pointer) (February 11, 2021)
- Exploit #2325 - cve-2016-0040 (Exploiting CVE-2016-0040 uninitialized pointer) (April 7, 2020)
- Exploit #2275 - CVE-2016-0040 (CVE-2016-0040 Privilege Escalation Exploit For WMI Receive Notification Vulnerability (x86-64)) (April 7, 2020)
- Exploit #1607 - Windows WMI Recieve Notification Exploit (March 18, 2020)