CVE-2016-0099
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."
- Affected products
- Windows, Windows 10, Windows 7, Windows 8.1, Windows Rt 8.1, Windows Server 2008, Windows Server 2012, Windows Vista
- Microsoft Windows 10 1507
- All versions
- Microsoft Windows 10 1511
- All versions
- Microsoft Windows 7
- All versions
- Microsoft Windows 8.1
- All versions
- Microsoft Windows Server 2008
- All versions
- Microsoft Windows Server 2012
- All versions
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 37.2% (98th percentile)
- Weakness
- CWE-120
- NVD status
- Analyzed
- Published
- 2016-03-09
CVE-2016-0099 at NVD
17 known exploits for CVE-2016-0099
Proof-of-concept code and exploit modules indexed by Sploitus
MS16-032
MS16-032-Cobalt-Strike-LPE-BOF
Exploit for Code Injection in Microsoft
Exploit for Code Injection in Microsoft
Immunity Canvas: MS16_135
MS16-032 Secondary Logon Handle local mention the right vulnerability
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Secondary Logon Handle Privilege Escalation
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Secondary Logon Handle Privilege Escalation (MS16-032) (Metasploit)
MS16-032 Secondary Logon Handle Privilege Escalation
Microsoft Windows 7 < 10 / Server 2008 < 2012 (x86/x64) - Privilege Escalation (MS16-032) (C#)
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Local Privilege Escalation (MS16-032)
Microsoft Windows 7 < 10 / Server 2008 < 2012 (x86/x64) - Privilege Escalation (MS16-032) (Pow
Microsoft Windows 7 < 10 / 2008 < 2012 R2 (x86/x64) - Local Privilege Escalation (MS16-032) (PowerShell)
MS16-032 Secondary Logon Handle Privilege Escalation
Microsoft Windows 8.1 / 10 (x86) - Secondary Logon Standard Handles Missing Sanitization Privilege E
Microsoft Windows 8.1/10 (x86) - Secondary Logon Standard Handles Missing Sanitization Privilege Escalation (MS16-032)
Immunity Canvas: MS16_032