Vulnerability Intelligence

🛡 CVE-2016-0099

Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
Microsoft Windows CWE-264

Ransomware use

KNOWN
CISA KEV

EPSS

37.2%
Elevated · 98th pct

Added to KEV

2022-03-03
CISA

Remediate by

2022-03-24
⚠ OVERDUE

CWE

CWE-264
weakness

📈 EPSS exploit probability

37.2%
FIRST EPSS — 30-day probability of exploitation in the wild · band Elevated · higher than 98% of all scored CVEs

⚠ KEV remediation overdue

CISA required federal remediation by 2022-03-24. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.

📄 Description

A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code a

🏹 Attributed exploitation

Malware / ransomware (KEV): ransomware (KEV-flagged)

Malware pivots: 🦠 ransomware 🦠 ransomware (KEV-flagged)

🛡 Add to case

Attach CVE-2016-0099 (Vulnerability / CVE) and pull all linked entities:
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php