CVE-2016-0151
KEV ransomware PoC massLocal Privilege Escalation in Microsoft Windows CSRSS (8.1/10, Server 2012)
CISA: Microsoft Windows CSRSS Security Feature Bypass Vulnerability
CVE-2016-0151 is a privilege management flaw (CWE-269) in the Microsoft Windows Client-Server Run-time Subsystem (CSRSS), which mishandles process tokens on Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1511, and Windows Server 2012 and 2012 R2. A local attacker can trigger it by running a specially crafted application on an affected system, requiring no special privileges. By mismanaging the process token, CSRSS allows the attacker to bypass intended security boundaries and gain elevated privileges, giving high confidentiality, integrity, and availability impact from a single local foothold. Any user of these Windows versions is affected, including endpoint users and servers where local code execution precedes broader compromise. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, and a public proof-of-concept exists (Exploit-DB 39740), with an EPSS 30-day exploitation probability of 63.2%.
What to do: Apply Microsoft's security updates for CSRSS on all affected Windows 8.1, RT 8.1, Windows 10 1507/1511, and Server 2012/2012 R2 systems per CISA's required action, prioritizing internet-reachable and endpoint-heavy environments given known ransomware use. Because Windows 10 1507/1511 and Server 2012/2012 R2 are beyond mainstream support on current patching tracks, upgrade to a supported Windows 10 build or patched servicing channel where updates are no longer available. Check for local privilege-escalation activity followed by ransomware deployment, and restrict execution of untrusted local code on any systems that cannot yet be patched.
| Microsoft Windows 10 | 1507 (Gold) and 1511 |
| Microsoft Windows 8.1 | all supported service branches at time of disclosure |
| Microsoft Windows RT 8.1 | all supported service branches at time of disclosure |
| Microsoft Windows Server 2012 | Server 2012 (Gold) and Server 2012 R2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
- Affected
- Microsoft Client-Server Run-time Subsystem (CSRSS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 8.1, windows rt 8.1, windows server 2012
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.