NVD disclosure day

Published threat advisories for April 12, 2016

CVE advisoryKnown Exploit

CVE-2016-0167

Microsoft Windows Local Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Local users can gain elevated privileges on affected Microsoft Windows systems by running a specially crafted application, potentially leading to unauthorized system access and data compromise. This vulnerability impacts the Win32k component and poses a business risk by affecting system integrity and enabling further m

• CISA KEV

CVE advisoryKnown Exploit

CVE-2016-0165

Microsoft Win32k Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Local users can gain elevated privileges in Microsoft Windows systems through a crafted application. This impacts organizations by potentially allowing unauthorized system access and control, leading to compromised integrity and data confidentiality. The business risk involves the potential for attackers to escalate th

• CISA KEV

CVE advisoryKnown Exploit

CVE-2016-0162

Microsoft Internet Explorer File Disclosure Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Microsoft Internet Explorer allows attackers to discover the existence of files. This could lead to information disclosure, increasing business risk for affected organizations. The potential for unauthorized access to file information requires attention.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2016-0151

Windows CSRSS Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows' Client-Server Run-time Subsystem could allow local users to gain elevated privileges through a crafted application. This impacts affected Windows systems by enabling unauthorized access and control over data and resources. The risk to business operations is significant due to potential data

• CISA KEV