Executive brief
The Secondary Logon Service in Microsoft Windows fails to properly process request handles in memory, leading to a privilege escalation vulnerability. A local attacker can exploit this by running a crafted application to gain administrator-level privileges.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1, 2012 Gold, 2012 R2
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 Gold
- Microsoft Windows RT 8.1 Gold
- Microsoft Windows 10 Gold, 1511
Timeline
- 2016-03-08: advisory: Microsoft Security Bulletin MS16-032 published
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: disclosed: NVD publication date