V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2016-0007
CVE
HighConfirmedExploit available

The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windo…

CVSS
7.8
High
EPSS
0.05
p91
Published
2016-01-01
Updated
2016-01-01
Description

The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0006.

Tags · CWE
LPE
CWE-264
Affected products
Windows_10Windows_7Windows_8Windows_8.1Windows_rtWindows_rt_8.1Windows_server_2008Windows_server_2012Windows_vista
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Timeline
2016-01-01
Published
2016-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.054 · p91
Known exploited (KEV)
No
Known exploits — Сканер-ВС
39310
exploitdb · https://www.exploit-db.com/exploits/39310
Enterprise
39311
exploitdb · https://www.exploit-db.com/exploits/39311
Enterprise
Affected products
ProductVendorStatus
windows_10*Tracked
windows_7*Tracked
windows_8*Tracked
windows_8.1*Tracked
windows_rt*Tracked
windows_rt_8.1*Tracked
windows_server_2008*Tracked
windows_server_2012*Tracked
windows_vista*Tracked
Source databases
CVE
Related vulnerabilities