7.8
CVSSv3

CVE-2016-3225

Published: 16/06/2016 Updated: 12/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 696
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application that forwards an authentication request to an unintended service, aka "Windows SMB Server Elevation of Privilege Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows rt 8.1

microsoft windows server 2012 r2

microsoft windows server 2012 -

microsoft windows 8.1

microsoft windows 7

microsoft windows server 2008 r2

microsoft windows 10 1511

microsoft windows 10 -

microsoft windows server 2008

microsoft windows vista

Exploits

## # This module requires Metasploit: metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## require 'msf/core/post/windows/reflective_dll_injection' class MetasploitModule < Msf::Exploit::Local Rank = NormalRanking include Msf::Post::File include Msf::Post::Windows::Priv include Msf::Post: ...

Github Repositories

GoodSecurity Penetration Test Report Date: 4/23/2022 UoT Cybersecurity Bootcamp 2022 G-Mully (g-mully@GoodSecuritycom) High-Level Summary GoodSecurity was tasked with performing an internal penetration test on GoodCorps CEO, Hans Gruber An internal penetration test is a dedicated attack against internally connected systems The focus of this test is to perform attacks, simi

Unit 17 Cybersecurity Bootcamp Penetration Activity.

GoodSecurity Penetration Test Report TamieBoychuk@GoodSecuritycom 29 March 2022 High-Level Summary GoodSecurity was tasked with performing an internal penetration test on GoodCorp’s CEO, Hans Gruber An internal penetration test is a dedicated attack against internally connected systems The goal of this test is to perform attacks similar to those of a hacker and attemp