CVE-2016-3309: Microsoft Windows Kernel Privilege Escalation Vulnerability
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.
Other sources
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3309?
CVE-2016-3309 is rated as a critical vulnerability that allows local users to gain elevated privileges.
How do I fix CVE-2016-3309?
To fix CVE-2016-3309, apply the security updates provided by Microsoft for the affected versions of Windows.
What versions of Windows are affected by CVE-2016-3309?
CVE-2016-3309 affects multiple versions including Windows Vista SP2, Windows 7 SP1, Windows 8.1, and Windows 10.
Who can exploit the CVE-2016-3309 vulnerability?
Local users can exploit CVE-2016-3309 through a crafted application to gain higher privileges on the affected system.
Is there a workaround for CVE-2016-3309?
There are no effective workarounds for CVE-2016-3309; updating the system is the recommended approach.