CVE-2016-3372: Microsoft Windows Server 2008
Medium severity, CVSS 6.6. EPSS: 2.2% chance of exploitation in the next 30 days.
The kernel API in Microsoft Windows Vista SP2 and Windows Server 2008 SP2 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
Affected products
Published 2016-09-14. Last modified 2026-06-17.