'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-07-20 | |
| Rule Name: | Microsoft Windows DFS client driver Privilege Elevation Vulnerability (CVE-2016-7185) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." a different vulnerability than CVE-2016-3266, CVE-2016-3376, and CVE-2016-7211. | |
| Impact: | Privilege escalation vulnerability in Windows DFS client driver via improper handle validation when mounting DFS shares, allowing a local attacker to elevate from user to SYSTEM by passing a malicious handle through SafeHandleZeroOrMinusOneIsInvalid to the kernel. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | https://nvd.nist.gov/vuln/detail/CVE-2016-7185 https://www.exploit-db.com/exploits/40572/ |
|
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |