CVE-2016-0151
microsoft windows 10 1507, microsoft windows 10 1511, microsoft windows 8.1
Published 12 Apr 2016 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 28 Mar 2022, with a remediation deadline of 18 Apr 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
References
- www.securitytracker.com/id/1035544 · Broken Link, Third Party Advisory, VDB Entry
- docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-048 · Patch, Vendor Advisory
- www.exploit-db.com/exploits/39740/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0151 · US Government Resource