CVE-2016-3371
MEDIUMMicrosoft Windows - Unauthorized Information Disclosure via Kernel API
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-3371. PoCs published by Google Security Research.
AI-analyzed exploit summary This C# PoC exploits CVE-2026-3371 by abusing NtLoadKeyEx to load a registry hive outside the hidden attachment point, allowing privilege escalation via COM moniker manipulation. It demonstrates a local privilege escalation (LPE) by registering a malicious type library that executes when WinLogon is signaled.
Description
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
Exploits (1)
This C# PoC exploits CVE-2026-3371 by abusing NtLoadKeyEx to load a registry hive outside the hidden attachment point, allowing privilege escalation via COM moniker manipulation. It demonstrates a local privilege escalation (LPE) by registering a malicious type library that executes when WinLogon is signaled.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N