🛡 CVE-2016-0099
Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
Microsoft Windows CWE-264
Ransomware use
KNOWN
CISA KEV
EPSS
37.2%
Elevated · 98th pct
Added to KEV
2022-03-03
CISA
Remediate by
2022-03-24
⚠ OVERDUE
CWE
CWE-264
weakness
📈 EPSS exploit probability
37.2%
FIRST EPSS — 30-day probability of exploitation in the wild · band Elevated · higher than 98% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2022-03-24. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code a
🏹 Attributed exploitation
Malware / ransomware (KEV): ransomware (KEV-flagged)
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron