Skip to content
COOEY

EXPOSURES › CVE-2016-0151

CVE-2016-0151

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-0151 ↗
⌖ EXPLOITED IN THE WILD SHAME 68/100 ransomwareexploited-in-wildunpatched

A Microsoft Windows flaw allowed local privilege escalation via crafted applications, actively exploited and linked to ransomware attacks.

CVE-2016-0151 involved CSRSS mismanaging process tokens, enabling local users to escalate privileges. DIB organizations using vulnerable Windows systems face increased ransomware risk and potential CMMC compliance failures; immediate patching and vulnerability scanning are critical.

Shame score — A fundamental process token management flaw in a core Windows component, actively exploited and linked to ransomware, demonstrates a significant security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized