CVE-2016-7188
HIGHWindows 10 - Privilege Escalation via Standard Collector Service Library Loading
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-7188. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a DLL hijacking vulnerability in the Windows Diagnostics Hub service by creating a named stream in the system32 directory, allowing arbitrary DLL loading with system privileges. The PoC demonstrates the flaw by abusing the insufficient fix for CVE-2016-3231.
Description
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability."
Exploits (1)
This exploit leverages a DLL hijacking vulnerability in the Windows Diagnostics Hub service by creating a named stream in the system32 directory, allowing arbitrary DLL loading with system privileges. The PoC demonstrates the flaw by abusing the insufficient fix for CVE-2016-3231.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H