Privilege escalation in Microsoft Windows - CVE-2016-7188
Published: October 11, 2016 / Updated: September 14, 2018
Vulnerability identifier: #VU979
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7188
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to obtain elevated privileges on the target system.
The weakness exists due to insufficient sanitization of user-supplied input by the Windows Diagnostics Hub Standard Collector Service. By executing a crafted application and causing unsecure library loading attackers can obtain root privileges on the affected system that allows them to execute arbitrary code with system privileges.
Succesful exploitation of the vulnerability may result in complete vulnerable system compromise.
The weakness exists due to insufficient sanitization of user-supplied input by the Windows Diagnostics Hub Standard Collector Service. By executing a crafted application and causing unsecure library loading attackers can obtain root privileges on the affected system that allows them to execute arbitrary code with system privileges.
Succesful exploitation of the vulnerability may result in complete vulnerable system compromise.
Affected software
Microsoft Windows
How to mitigate CVE-2016-7188
Cybersecurity Help is currently unaware of any official patch addressing the vulnerability.