CVE-2016-0151 KEV EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 62.9% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-18.
Description
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 62.94% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-269 |
| On CISA KEV | yes — remediate by 2022-04-18 |
| Public exploit | yes |
| Published | 2016-04-12 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft Windows CSRSS Security Feature Bypass Vulnerability |
|---|---|
| Added | 2022-03-28 |
| Due | 2022-04-18 |
| Vendor / product | Microsoft / Client-Server Run-time Subsystem (CSRSS) |
| Ransomware use | known |
Affected (5)
| Vendor | Product |
|---|---|
| microsoft | windows 10 1507 |
| microsoft | windows 10 1511 |
| microsoft | windows 8.1 |
| microsoft | windows rt 8.1 |
| microsoft | windows server 2012 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows - CSRSS BaseSrvCheckVDM Session 0 Process Creation Privilege Escalation (MS16-048) | 2016-04-27 |
References
- http://www.securitytracker.com/id/1035544
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-048
- https://www.exploit-db.com/exploits/39740/
- http://www.securitytracker.com/id/1035544
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-048
- https://www.exploit-db.com/exploits/39740/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0151
→ the Explorer · watch your stack · NVD