vendor:
Windows 7
by:
Nabeel Ahmed
8,1
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Windows 7
Affected Version From: Windows 7 Professional (x32/x64)
Affected Version To: Windows 7 Professional (x32/x64)
Patch Exists: YES
Related CWE: CVE-2016-3223
CPE: o:microsoft:windows_7
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
Group Policy Elevation of Privilege Vulnerability
This vulnerability allows an attacker to create/modify local Administrator account through a fake Domain Controller by creating User Configuration Group Policies.
Mitigation:
Ensure that all systems are patched and up-to-date, and that users are not given unnecessary privileges.