CVE-2016-0151
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
- Affected products
- Windows, Windows 10, Windows 8.1, Windows Rt 8.1, Windows Server 2012, Windows Server 2012 R2
- Microsoft Windows 10 1507
- All versions
- Microsoft Windows 10 1511
- All versions
- Microsoft Windows 8.1
- All versions
- Microsoft Windows Rt 8.1
- All versions
- Microsoft Windows Server 2012
- All versions
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 63.2% (99th percentile)
- Weakness
- CWE-269
- NVD status
- Analyzed
- Published
- 2016-04-12
CVE-2016-0151 at NVD
2 known exploits for CVE-2016-0151
Proof-of-concept code and exploit modules indexed by Sploitus