Skip to content
COOEY

EXPOSURES › CVE-2016-0167

CVE-2016-0167

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-0167 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatchedrce

A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.

CVE-2016-0167 in Microsoft Win32k enabled privilege escalation via crafted applications, with active exploitation and ransomware connections. DIB organizations relying on Windows must ensure timely patching and hardening to prevent unauthorized access and data compromise, directly impacting CMMC compliance. Failure to remediate exposes systems to potential ransomware infection and data exfiltration.

Shame score — The vulnerability's exploitation in ransomware attacks highlights a significant failure in Microsoft's security posture and a lack of diligence in patching, despite its age.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Microsoft Win3k vulnerability (CVE-2016-0167) is flagged as critical and exploited, indicating severe security posture failure.
recentbreaches.com ↗ severe-fallout -0.90
severe-fallout
"Microsoft 48 breaches tracked"
cooey ↗ severe-fallout -0.50
neutral
"Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application"
cvefeed.io ↗ severe-fallout -0.40
negative
"CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
securityonline.info ↗ severe-fallout -0.30
negative
"CVE Watchtower • Daily CyberSecurity"
app.opencve.io ↗ severe-fallout -0.20
neutral
"Microsoft CVEs and Security Vulnerabilities - OpenCVE"
www.cvefind.com ↗ severe-fallout -0.10
neutral
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
www.microsoft.com ↗ severe-fallout +0.00
neutral
"Microsoft Security Blog"
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized