CVE-2016-0099
Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
7.8
CVSS 3.1
37.0 %
EPSS (current)
2022-03-03
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Microsoft / Windows
Published: 2016-03-09 · Due (CISA): 2022-03-24
CWE: CWE-120 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| exploitdb | 39574 | Microsoft Windows 8.1/10 (x86) - Secondary Logon Standard Handles Missing Sanitization Privilege Escalation (MS16-032) | 2016-03-21 |
| metasploit | exploit/windows/local/ms16_032_secondary_logon_handle_privesc | exploit/windows/local/ms16_032_secondary_logon_handle_privesc | 2016-03-21 |
| exploitdb | 39719 | Microsoft Windows 7 < 10 / 2008 < 2012 R2 (x86/x64) - Local Privilege Escalation (MS16-032) (PowerShell) | 2016-04-21 |
| exploitdb | 39809 | Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Local Privilege Escalation (MS16-032) | 2016-04-25 |
| exploitdb | 40107 | Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Secondary Logon Handle Privilege Escalation (MS16-032) (Metasploit) | 2016-07-13 |
References only — no downloads or instructions.