Skip to content
Appaloosa Scout
Language selector
fr en

Materialized exploit

CVE-2016-0173

HIGH

1 public exploit(s) for this CVE, 1 materialized with their code.

For defensive research only. Only test on systems you own or have written authorization for. Unauthorized access is illegal.
ExploitDB dos windows Verified
Source

Microsoft Windows 7 - win32k Bitmap Use-After-Free (MS16-062) (2)

By Nils Sommer

How to test this exploit

Denial of service: sends malformed input to crash the service. Test in an isolated VM, the effect is destructive.

Code txt

Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=747

The attached PoC crashes 32-bit Windows 7 with special pool enabled on win32k.sys. It might take several runs in order to reproduce. Tested the PoC on a single core VM.


Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39960.zip