PoC Index

CVE-2016-0151

KEV RANSOMWAREHIGH 7.8EPSS 63.2%

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
63.20% chance of exploitation in the next 30 days, 99th percentile
CISA KEV
added 2022-03-28, used in ransomware campaigns
Published
2016-04-12
Updated
2025-10-21

ExploitDB entries (1)

References

Related