CVE-2016-3225
HIGH EXPLOITEDMicrosoft Windows SMB Server - Local Privilege Escalation via Authentication Request Forwarding
Title source: llmExploitation Summary
CVE-2016-3225 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 4 public exploits from researchers including Metasploit, FoxGloveSec, breenmachine, decoder, ohpe, phra, lupman, FoxGloveSec, breenmachine, Mumbai, including a Metasploit module exploits/windows/local/ms16_075_reflection_juicy.
AI-analyzed exploit summary This Metasploit module exploits CVE-2016-3225, a Windows privilege escalation vulnerability leveraging Net-NTLMv2 reflection via DCOM/RPC to achieve SYSTEM privileges. It uses reflective DLL injection to execute the exploit payload in a target process, requiring the SeImpersonatePrivilege.
Description
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application that forwards an authentication request to an unintended service, aka "Windows SMB Server Elevation of Privilege Vulnerability."
Exploits (4)
This Metasploit module exploits CVE-2016-3225, a Windows privilege escalation vulnerability leveraging Net-NTLMv2 reflection via DCOM/RPC to achieve SYSTEM privileges. It uses reflective DLL injection to execute the exploit payload in a target process, requiring the SeImpersonatePrivilege.
This Metasploit module exploits CVE-2016-3225, a Windows Net-NTLMv2 reflection vulnerability in DCOM/RPC, to achieve SYSTEM-level privilege escalation. It uses reflective DLL injection to execute a payload in a spawned notepad.exe process, leveraging the SeImpersonatePrivilege.
This Metasploit module exploits CVE-2016-3225 by leveraging Net-NTLMv2 reflection between DCOM/RPC to achieve a SYSTEM handle for privilege escalation. It uses reflective DLL injection to execute the RottenPotato exploit, which abuses the SeImpersonatePrivilege to escalate privileges.
This repository contains documentation and configuration scripts for a collection of Windows kernel exploits, including CVE-2003-0352, CVE-2006-3439, and others. It includes README files in both Chinese and English, as well as a Python script for generating documentation.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H