CVE-2016-0073
MEDIUMWindows Kernel - Local Privilege Escalation via Registry API Call
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-0073. PoCs published by Google Security Research.
AI-analyzed exploit summary The provided C# code demonstrates a local privilege escalation (LPE) exploit for CVE-2016-0073, leveraging impersonation token manipulation to create arbitrary registry keys in another user's hive. It uses S4U logon to impersonate a privileged user and exploits the DeviceApi CMApi vulnerability to bypass access checks.
Description
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0075.
Exploits (1)
The provided C# code demonstrates a local privilege escalation (LPE) exploit for CVE-2016-0073, leveraging impersonation token manipulation to create arbitrary registry keys in another user's hive. It uses S4U logon to impersonate a privileged user and exploits the DeviceApi CMApi vulnerability to bypass access checks.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N