Vulnerability record · CVE-2016-0099 · published 9 March 2016
CVE-2016-0099: Windows Secondary Logon Service handle handling privilege escalation
Microsoft · Windows 10 1507
The Secondary Logon Service in multiple Windows versions fails to properly process request handles, a flaw classified as a classic buffer overflow (CWE-120). A local user can run a crafted application to elevate privileges on the affected host. Because it yields full system rights from a low-privileged local account, it is a standard post-compromise escalation step.
Description
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with known ransomware use and public exploits, but requires an existing local foothold and low privileges rather than remote access.
What it is
The Secondary Logon Service in multiple Windows versions fails to properly process request handles, a flaw classified as a classic buffer overflow (CWE-120). A local user can run a crafted application to elevate privileges on the affected host. Because it yields full system rights from a low-privileged local account, it is a standard post-compromise escalation step.
Impact
An attacker with a local foothold gains elevated privileges, typically SYSTEM, on the target machine. That access enables credential theft, disabling of security controls and lateral movement.
Attack surface
Reached locally by executing a crafted application on the affected Windows host; the CVSS vector AV:L/PR:L/UI:N indicates a local attacker with low privileges and no user interaction. No remote or network path is described.
Exploitation
CISA KEV lists it as exploited in the wild with known ransomware campaign use, and multiple public Exploit-DB entries exist; EPSS 30-day probability is 0.372 (98.4th percentile).
What to do
- Apply the Microsoft MS16-032 security update to all affected Windows versions, prioritizing Windows 7, 8.1, Server 2008/2012 and Windows 10 Gold/1511.
- Retire or isolate unsupported builds such as Vista SP2 and Windows Server 2008 SP2/R2 SP1 that cannot be patched.
- Restrict local logon and interactive access so untrusted users cannot run arbitrary code on these hosts.
- Monitor and constrain use of the Secondary Logon (seclogon) service where business needs allow.
- Hunt for and remove commodity privilege-escalation tooling and scripts that target this flaw.
Detection
- Alert on unexpected child processes spawned by seclogon or svchost hosting the Secondary Logon service.
- Monitor for processes gaining SYSTEM integrity from a medium-integrity parent, especially short-lived executables in user-writable paths.
- Correlate local privilege-escalation exploit artifacts with subsequent credential dumping or ransomware behavior.
- Audit hosts still running unpatched builds listed in MS16-032 and flag them for remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2016-0099 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0099 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0099), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.