CVE Vulnerabilities

CVE-2016-3372

Published: Sep 14, 2016 | Modified: Apr 12, 2025
CVSS 3.x
6.6
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The kernel API in Microsoft Windows Vista SP2 and Windows Server 2008 SP2 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka Windows Kernel Elevation of Privilege Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Windows_server_2008Microsoft**
Windows_vistaMicrosoft**

References