The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
Use CWE-269, Microsoft vendor hub and Windows 10 1507 product page to widen CVE-2016-0151 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-59295, CVE-2025-64680 and CVE-2025-64679 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.