Rapid7 Vulnerability & Exploit Database

MS16-048: Security Update for CSRSS (3148528)

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

MS16-048: Security Update for CSRSS (3148528)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
04/12/2016
Created
07/25/2018
Added
04/12/2016
Modified
05/03/2022

Description

A security feature bypass vulnerability exists in Microsoft Windows when the Client-Server Run-time Subsystem (CSRSS) fails to properly manage process tokens in memory.

Solution(s)

  • WINDOWS-HOTFIX-MS16-037-1f7b2d51-98a1-4240-a636-8096fa0308c3
  • WINDOWS-HOTFIX-MS16-037-34515df7-3d11-4fa9-98ad-77c6f0dafc2a
  • WINDOWS-HOTFIX-MS16-037-45da2895-fcf0-4175-a533-e0fda3dbc081
  • WINDOWS-HOTFIX-MS16-037-4d0814f6-9f22-43aa-b23c-f6243b1e1f4a
  • WINDOWS-HOTFIX-MS16-048-209e2d1e-330f-4dcc-b705-5999c2f38385
  • WINDOWS-HOTFIX-MS16-048-31ef3e41-23ce-4c45-b65d-868f46573f11
  • WINDOWS-HOTFIX-MS16-048-42741710-9a4c-46c6-a3cd-bbc844ae51ca
  • WINDOWS-HOTFIX-MS16-048-be906749-1c85-464e-8205-09d804c36bfd
  • WINDOWS-HOTFIX-MS16-048-c3ad4ced-532d-4969-b2b7-e41d9560d3ea
  • WINDOWS-HOTFIX-MS16-048-f7956e11-7b6b-4310-95e9-9522e2d891fb

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;