CVE-2016-0135 is an elevation of privilege vulnerability affecting the Secondary Logon Service in Microsoft Windows 10 Gold and 1511. A local attacker can exploit this by running a specially crafted application, leading to high impact on confidentiality, integrity, and availability. With a CVSSv3 score of 8.4 (High), it presents a significant risk if exploited. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Microsoft Windows 10 lsass.exe Empty SID Lookup Handling Remote DoS
Apr 14, 2016[R1] Microsoft Windows 10 lsass.exe Empty SID Lookup Handling Remote DoS
Apr 13, 2016[R1] Microsoft Windows 10 lsass.exe Empty SID Lookup Handling Remote DoS
Apr 13, 2016Secondary Logon Elevation of Privilege Vulnerability
Apr 12, 2016