CVE-2016-0099
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
36.9%
98.4th percentile
CISA KEV
Listed
Added 2022-03-03 · patch by 2022-03-24
Weakness / dates
—
Published — · modified —
Description
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator.