← Back to browse · API

CVE-2016-0099

Severity
HIGH
CVSS
7.8
EPSS
0.37164
Risk score
69.21
CISA KEV
Yes
PoC
No
Published
2016-03-09
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2016-0137, GHSA-FQ5J-826M-H5WC
Products
Microsoft:Windows, n/a:n/a n/a
Sources
cisa.gov CVE-2016-0099
euvd EUVD-2016-0137

Description

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."

References