CVE-2016-7255: Microsoft Win32k Privilege Escalation Vulnerability
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Other sources
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7255?
CVE-2016-7255 is rated as important, indicating a significant risk of privilege escalation.
How do I fix CVE-2016-7255?
To fix CVE-2016-7255, apply the latest security updates provided by Microsoft for affected Windows versions.
What versions of Windows are affected by CVE-2016-7255?
CVE-2016-7255 affects multiple versions including Windows Vista SP2, Windows 7 SP1, Windows 10, Windows Server 2008 SP2, and more.
What type of vulnerability is CVE-2016-7255?
CVE-2016-7255 is a privilege escalation vulnerability in the kernel-mode drivers of the Windows operating system.
Can attackers exploit CVE-2016-7255 remotely?
No, CVE-2016-7255 requires local access for exploitation, allowing local users to gain elevated privileges.