CVE-2016-0151CISA KEV
Microsoft Windows CSRSS Security Feature Bypass Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
- Product
- Client-Server Run-time Subsystem (CSRSS)
- Added to KEV
- 28 Mar 2022
- Federal remediation due
- 18 Apr 2022
- Known ransomware use
- Yes