Microsoft Security Bulletin MS16-014 - Security Update for Microsoft Windows to Address Remote Code Execution (3134228)

Description: An elevation of privilege vulnerability exists when the Windows kernel improperly handles objects in memory. The update addresses the vulnerabilities by correcting how the Windows kernel handles objects in memory. To exploit the vulnerability an authenticated attacker must send a specially-crafted network packet to a server running the Microsoft Windows 7 SP1 (x86) system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker who successfully exploited the vulnerability could run arbitrary code in kernel mode.

Operating System: Windows 7 SP1 (x86)
CVE: CVE-2016-0400, CVE-2016-0049

Related vulnerabilities:
- MS15-034: Windows HTTP.sys Remote Code Execution
- MS15-132: Event Viewer Snapin / Windows Vista - 7 / Office 2007 - 2013
- MS16-025: Windows Mail Find People / Windows Vista / Office 2010
- MS08-014: Microsoft Office Excel Code Execution Exploit

Available tools:
- Windows-Exploit-Suggester: This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins.
- ETERNALBLUE: A remote kernel exploit originally targeting the Server Message Block (SMB) service on Microsoft Windows XP (Server 2003) and Microsoft Windows 7 (Server 2008).