CVE-2016-0075
MEDIUMMicrosoft Windows 8.1/10, Server 2012, RT 8.1 - Local Privilege Escalation via Registry API
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-0075. PoCs published by Google Security Research.
AI-analyzed exploit summary The provided C# code is a functional proof-of-concept exploit for CVE-2016-0075, which leverages the DeviceApi CMApi PiCMOpenClassKey IOCTL to create arbitrary registry keys in the system hive, leading to elevation of privilege (EoP) on Windows 10 10586.
Description
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0073.
Exploits (1)
The provided C# code is a functional proof-of-concept exploit for CVE-2016-0075, which leverages the DeviceApi CMApi PiCMOpenClassKey IOCTL to create arbitrary registry keys in the system hive, leading to elevation of privilege (EoP) on Windows 10 10586.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N