CVE-2016-0099
KEV ransomware PoC ×4massLocal Privilege Escalation in Microsoft Windows Secondary Logon Service
CISA: Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
CVE-2016-0099 is a privilege escalation flaw in the Windows Secondary Logon Service, which fails to properly manage request handles in memory. An attacker who can already execute code on a vulnerable Windows system triggers the flaw through the service's request handling and gains the ability to run arbitrary code as administrator, converting a low-privilege foothold into full system control. Microsoft Windows systems lacking the vendor's updates are affected; the CISA data lists the impacted product only as 'Microsoft Windows' without specific version ranges. Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, and EPSS places the 30-day exploitation probability at 37.2% (98th percentile). No public proof-of-concept is cataloged in the source data.
What to do: Apply Microsoft's March 2016 security updates (MS16-032) on all Windows systems, per the vendor instructions required by the CISA KEV entry, prioritizing legacy and internet-reachable hosts. On systems that cannot be patched, disable the Secondary Logon service as a mitigation (noting that 'Run as' will stop working), and hunt for local privilege-escalation and ransomware-staging activity on unpatched Windows machines.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 7, windows 8.1, windows server 2008, windows server 2012, windows vista
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H