CVE-2016-0099
גבוהה 7.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 37% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-120
מוצרים מושפעים
microsoft: windows 10 1507; microsoft: windows 10 1511; microsoft: windows 7; microsoft: windows 8.1; microsoft: windows server 2008; microsoft: windows server 2012; microsoft: windows vista
קישורים
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-… PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-… PatchVendor Advisory
- https://www.exploit-db.com/exploits/39574/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39719/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39809/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/40107/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39574/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39719/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39809/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/40107/ ExploitThird Party AdvisoryVDB Entry