CVE-2016-0151
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-03-28Remediation due 2022-04-18
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
7.8
CVSS
62.9%
EPSS (exploit prob.)
99th
EPSS percentile
2016-04-12
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-269
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_10_1507 | all versions |
| microsoft | windows_10_1511 | all versions |
| microsoft | windows_8.1 | all versions |
| microsoft | windows_rt_8.1 | all versions |
| microsoft | windows_server_2012 | all versions |
| microsoft | windows_server_2012 | r2 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securitytracker.com/id/1035544
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-048
- https://www.exploit-db.com/exploits/39740/
- http://www.securitytracker.com/id/1035544
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-048
- https://www.exploit-db.com/exploits/39740/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0151
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-0151