A vulnerability in the SMB server component of multiple Microsoft Windows versions allows a local attacker to gain elevated privileges. The vulnerability is exploited by forwarding an authentication request from a crafted application to an unintended service, resulting in privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module: 'ms16_075_reflection_juicy.rb', which implements a local privilege escalation exploit for Windows systems vulnerable to CVE-2016-3225 (MS16-075). The exploit leverages the Juicy Potato technique, which abuses Net-NTLMv2 reflection via DCOM/RPC to obtain a SYSTEM handle and elevate privileges. The module is designed for use with Meterpreter sessions and supports both x86 and x64 architectures. It requires the target session to have the SeImpersonatePrivilege and to be running on a Windows version prior to 10 1803 or Windows Server 2019. The exploit works by spawning a notepad.exe process, injecting a DLL (juicypotato.x86.dll or juicypotato.x64.dll) into it, and executing a user-supplied payload as SYSTEM. The module allows customization of the DCOM CLSID, RPC server host/port, and listening address/port. The main file is well-structured, with clear separation of initialization, privilege checks, process creation, DLL injection, and exploit execution. The purpose of the repository is to provide a reliable, operational privilege escalation exploit for supported Windows targets within the Metasploit framework.
This repository contains a single Metasploit module: 'ms16_075_reflection.rb', which exploits the Windows Net-NTLMv2 Reflection vulnerability (MS16-075, CVE-2016-3225) for local privilege escalation. The exploit leverages DCOM/RPC reflection to obtain a SYSTEM handle, allowing the attacker to impersonate the SYSTEM token. The module requires a Meterpreter session with SeImpersonatePrivilege on the target and supports both x86 and x64 architectures by injecting the appropriate RottenPotato DLL. The exploit does not directly spawn a SYSTEM shell but enables token impersonation, which can be used to escalate privileges. The code is operational and integrates with the Metasploit framework, allowing the user to supply custom payloads. No network endpoints are present; the attack vector is local privilege escalation. The only fingerprintable endpoints are the DLL files used for the exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.