LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2016-0151: Microsoft Windows CSRSS Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2016-0151 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.

CVE-2016-0151 is a security feature bypass in the Microsoft Client-Server Run-time Subsystem (CSRSS) on Windows. CSRSS mismanages process tokens, allowing a local user to elevate privileges by running a crafted application. This matters because successful local privilege escalation can turn a foothold into full system control, and the vulnerability has been associated with ransomware activity. Defenders should treat it as a high-priority local elevation risk on affected Windows hosts and confirm exact scope against the vendor advisory.

How it works

The weakness falls under CWE-264 (Permissions, Privileges, and Access Controls). CSRSS is a core Windows component that handles certain process and session management tasks. According to the public description, it mishandles process tokens. An attacker who already has the ability to run code as a standard local user can supply a crafted application that abuses this mismanagement to obtain higher privileges on the same machine.

No remote code execution is implied by the given details; the attack path is local. Exact token-handling mechanics, required privileges for the initial foothold, and any specific API or object abuse are not detailed in the provided facts and must be confirmed against the Microsoft advisory. In practice, once elevated, an attacker can disable defenses, move laterally, or deploy follow-on payloads, including ransomware where this CVE has been observed in use.

Am I affected? How to find it in your systems

CSRSS ships as part of Windows itself, so the vulnerability can appear on workstations and servers that have not received the corresponding Microsoft update. Inventory every Windows endpoint and server, including virtual machines, golden images, and any systems that are infrequently patched.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2016-0151 exactly as directed in the vendor advisory and the CISA-required action: “Apply updates per vendor instructions.” Deploy through your normal test-and-rollout process, prioritizing internet-facing jump hosts, shared workstations, and any systems where unprivileged users can run arbitrary code.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface and increase detection confidence.

If your data may have been exposed

Actively exploited local elevation vulnerabilities are frequently used after initial access to deploy ransomware or exfiltrate data. If you have evidence of exploitation or have not yet patched, assume the host may have been compromised, perform incident response (isolate, image, credential reset, and hunt for persistence), and review whether sensitive data or credentials were accessible from that system. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora and then force password resets and enable stronger authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Client-Server Run-time Subsystem (CSRSS)
WeaknessCWE-264
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities