LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-0099: Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-0099 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this…

CVE-2016-0099 is a privilege escalation vulnerability in Microsoft Windows affecting the Secondary Logon Service. When that service mishandles request handles in memory, a local attacker can elevate to administrator-level rights and run arbitrary code. It matters because successful exploitation turns limited access into full control of the host, and this issue has been used in ransomware campaigns. Confirm exact product scope and fixed builds against the Microsoft advisory.

How it works

The weakness falls under CWE-264 (permissions, privileges, and access controls). The Secondary Logon Service is responsible for running processes under alternate credentials. According to the CISA summary, it fails to properly manage request handles in memory. An attacker who already has a foothold on the system can abuse that mismanagement to obtain higher privileges and execute code as an administrator. Public detail on exact memory layout or trigger sequences is limited; treat any exploit descriptions outside the vendor advisory as unverified. The practical outcome is local elevation of privilege, which is commonly chained after initial access to deploy further payloads, including ransomware.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Secondary Logon Service (the service that supports “Run as” / secondary logon functionality). It is present on typical desktop and server installations unless the service has been deliberately disabled.

If you cannot map a host to a patched build listed by Microsoft, treat it as potentially vulnerable until confirmed.

How to remediate

Patch first. Apply the security updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA (“Apply updates per vendor instructions”). Use your standard patch pipeline—WSUS, ConfigMgr, Intune, or equivalent—to deploy the correct packages for each Windows edition and architecture.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk:

Schedule the official update as soon as possible; compensating controls are temporary.

If your data may have been exposed

Privilege-escalation flaws that are actively exploited, including those used by ransomware operators, frequently precede data theft or encryption. If you have evidence of exploitation or ransomware activity on affected hosts, follow your incident-response plan: isolate systems, preserve volatile evidence, reset credentials for privileged accounts, and assess what data the elevated attacker could reach. You can also run a free exposure scan of your email addresses against known breach datasets to see whether associated credentials or personal data already appear in public dumps, then force password changes and enable multi-factor authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-264
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities