CVE-2016-3309
Description
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.
In plain language
AI Act nowCVE-2016-3309 is a Windows flaw where a low-privilege local attacker can use a specially crafted app to take over the whole machine; if you run affected Windows versions, you should act urgently by installing Microsoft’s fix.
CVE-2016-3309 is a local privilege-escalation flaw in Microsoft Windows kernel-mode drivers: an attacker with initial low-level access can run a crafted application to gain higher system privileges and potentially full control, with real-world exploitation reported by CISA in ransomware campaigns.
What to do now
- Check which Windows versions and service packs you run, and confirm whether the Microsoft security update MS16-098 is installed.
- If you are on a vulnerable Windows version, install the Microsoft fix for CVE-2016-3309 by applying MS16-098 per Microsoft’s guidance.
- After patching, verify the update is present, then review logs/alerts for any suspicious local execution attempts or unusual privilege changes around the same timeframe.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-3309 and every CVE in our database. Create a free account — no credit card required.
Create Free Account