CVE-2016-3236
CRITICALMicrosoft Windows - SSRF
Title source: llmDescription
The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles proxy discovery, which allows remote attackers to redirect network traffic via unspecified vectors, aka "Windows WPAD Proxy Discovery Elevation of Privilege Vulnerability."
Exploits (1)
metasploit
WORKING POC
by vvalien, hdm, tombkeeper · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/server/netbios_spoof_nat.rb
Scores
CVSS v3
9.8
EPSS
0.7800
EPSS Percentile
99.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-19
Status
published
Products (10)
microsoft/windows_10
microsoft/windows_10
1511
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_2008
microsoft/windows_server_2008
r2 sp1
microsoft/windows_server_2012
microsoft/windows_server_2012
r2
microsoft/windows_vista
Published
Jun 16, 2016
Tracked Since
Feb 18, 2026