VULNERABILITY INTELLIGENCE

CVE-2016-3372

CVSS score6.6 MEDIUM
EPSS probability2.23%
CISA KEVNot currently listed
Published2016-09-14
Last modified2026-06-17

Description

The kernel API in Microsoft Windows Vista SP2 and Windows Server 2008 SP2 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."