CVE-2016-0151
גבוהה 7.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Windows CSRSS Security Feature Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 63% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-269
מוצרים מושפעים
microsoft: windows 10 1507; microsoft: windows 10 1511; microsoft: windows 8.1; microsoft: windows rt 8.1; microsoft: windows server 2012
קישורים
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-… PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-… PatchVendor Advisory
- https://www.exploit-db.com/exploits/39740/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/39740/ ExploitThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035544 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035544 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource