CVE-2016-0167
Microsoft Windows Server 2008 r2
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2016-0167 is a high-severity an unspecified weakness vulnerability in Microsoft Windows Server 2008. Its CVSS base score is 7.8 (High).
Operationally, ranked in the top 8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The vulnerability CVE-2016-0167 resides in the kernel-mode driver component of Microsoft Windows, specifically identified as a Win32k elevation of privilege flaw. It affects Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511. The issue permits local users to gain elevated privileges by supplying a crafted application and is distinct from the related flaws CVE-2016-0143 and CVE-2016-0165.
An attacker who can execute code locally on an affected system, such as through a malicious application run by a standard user, can leverage the flaw to obtain higher privileges. The CVSS 7.8 rating indicates a local attack vector with low complexity that requires user interaction but can result in full confidentiality, integrity, and availability impact.
Microsoft security bulletin MS16-039 addresses the issue with available patches for the listed Windows versions and includes mitigation recommendations for administrators.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2016-0205
Vulnerability Data
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain…
more
privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0165.
- CWE(s)
- KEV Date Added
- 03 November 2021
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.