Junglewise Threat Intelligence

CVE-2016-0151: Microsoft Windows CSRSS Security Feature Bypass Vulnerability

CVE-2016-0151 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Windows 10, Microsoft Windows 8.1, Microsoft Windows Server 2012, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows mismanages process tokens, leading to a security feature bypass. A local attacker can exploit this by running a specially crafted application to elevate privileges on the target system.

Affected products

  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT 8.1
  • Microsoft Windows 10 Gold, 1511

Timeline

  • 2016-04-12: patched: Microsoft released security bulletin MS16-048 to address the issue.
  • 2016-04-27: exploited: Exploit published on Exploit-DB.
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.