ZeroHour

CVE-2016-0151

KEV ransomware PoC mass

Local Privilege Escalation in Microsoft Windows CSRSS (8.1/10, Server 2012)

CISA: Microsoft Windows CSRSS Security Feature Bypass Vulnerability

CVSS 3.1
7.8 high
EPSS
63%p99
Published
()
KEV added
AI analysis

CVE-2016-0151 is a privilege management flaw (CWE-269) in the Microsoft Windows Client-Server Run-time Subsystem (CSRSS), which mishandles process tokens on Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1511, and Windows Server 2012 and 2012 R2. A local attacker can trigger it by running a specially crafted application on an affected system, requiring no special privileges. By mismanaging the process token, CSRSS allows the attacker to bypass intended security boundaries and gain elevated privileges, giving high confidentiality, integrity, and availability impact from a single local foothold. Any user of these Windows versions is affected, including endpoint users and servers where local code execution precedes broader compromise. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, and a public proof-of-concept exists (Exploit-DB 39740), with an EPSS 30-day exploitation probability of 63.2%.

What to do: Apply Microsoft's security updates for CSRSS on all affected Windows 8.1, RT 8.1, Windows 10 1507/1511, and Server 2012/2012 R2 systems per CISA's required action, prioritizing internet-reachable and endpoint-heavy environments given known ransomware use. Because Windows 10 1507/1511 and Server 2012/2012 R2 are beyond mainstream support on current patching tracks, upgrade to a supported Windows 10 build or patched servicing channel where updates are no longer available. Check for local privilege-escalation activity followed by ransomware deployment, and restrict execution of untrusted local code on any systems that cannot yet be patched.

Affected
Microsoft Windows 101507 (Gold) and 1511
Microsoft Windows 8.1all supported service branches at time of disclosure
Microsoft Windows RT 8.1all supported service branches at time of disclosure
Microsoft Windows Server 2012Server 2012 (Gold) and Server 2012 R2
Estimated exposure
masstens of millions of devices historically ran these Windows versions; current unpatched installs likely in the millions but not precisely countable — Windows 8.1/RT 8.1 and Windows 10 1507/1511 shipped on hundreds of millions of consumer and enterprise PCs and Windows Server 2012/2012 R2 was a dominant server release, so the candidate population is mass-scale even though the number of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Client-Server Run-time Subsystem (CSRSS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 8.1, windows rt 8.1, windows server 2012
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.