CVE-2016-7225
MEDIUMWindows 10 and Windows Server 2016 - Privilege Escalation via VHD Driver
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-7225. PoCs published by Google Security Research.
AI-analyzed exploit summary This C# PoC exploits CVE-2016-7225, an arbitrary file deletion vulnerability in the Windows VHDMP driver due to unsafe ZwDeleteFile calls without OBJ_FORCE_ACCESS_CHECK. It abuses symbolic links to redirect deletions to arbitrary files, leading to privilege escalation.
Description
Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."
Exploits (1)
This C# PoC exploits CVE-2016-7225, an arbitrary file deletion vulnerability in the Windows VHDMP driver due to unsafe ZwDeleteFile calls without OBJ_FORCE_ACCESS_CHECK. It abuses symbolic links to redirect deletions to arbitrary files, leading to privilege escalation.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N