365
VMScore

CVE-2016-7224

Published: 10/11/2016 Updated: 12/10/2018
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.1 | Impact Score: 4.2 | Exploitability Score: 1.8
VMScore: 365
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2012 r2

microsoft windows server 2012 -

microsoft windows 10 1511

microsoft windows 8.1

microsoft windows rt 8.1

microsoft windows 10 -

microsoft windows 10 1607

microsoft windows server 2016 -

Exploits

/* Source: bugschromiumorg/p/project-zero/issues/detail?id=916 Windows: VHDMP Arbitrary Physical Disk Cloning EoP Platform: Windows 10 10586 No idea about 14393, 7 or 81 versions Class: Elevation of Privilege Summary: The VHDMP driver doesn’t open physical disk drives securely when creating a new VHD leading to information disclosu ...