⚠️ CISA Known Exploited Vulnerability
Active ThreatThis vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.
CVE-2016-0151
High CISA KEVVulnerability Description
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Known Affected Software
6 configuration(s) from 1 vendor(s)
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*
References & Resources
-
http://www.securitytracker.com/id/1035544secure@microsoft.com Broken Link Third Party Advisory VDB Entry
-
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-048secure@microsoft.com Patch Vendor Advisory
-
https://www.exploit-db.com/exploits/39740/secure@microsoft.com Exploit Third Party Advisory VDB Entry
-
http://www.securitytracker.com/id/1035544af854a3a-2127-422b-91ae-364da2661108 Broken Link Third Party Advisory VDB Entry
-
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-048af854a3a-2127-422b-91ae-364da2661108 Patch Vendor Advisory
-
https://www.exploit-db.com/exploits/39740/af854a3a-2127-422b-91ae-364da2661108 Exploit Third Party Advisory VDB Entry
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0151134c704f-9b21-4f2e-91b3-4a467353bcc0
Severity Details
CISA KEV Status
Listed in CISA's Known Exploited Vulnerabilities catalog
Key Information
- Published Date
- April 12, 2016
