cbcvebase.
CVE-2011-2016
published 2011-11-08

CVE-2011-2016: Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and…

PriorityP335high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
8.10%
94.2th percentile
Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."

Affected

13 ranges
VendorProductVersion rangeFixed in
drupalphpmailer_3rd_party_library
hackeronewebdriver-launcher_node_module0 – 0.1.3
microsoftwindows_server_2008
msrcmicrosoft_excel_for_mac_2011
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_compatibility_pack_service_pack_3
msrcmicrosoft_office_web_apps_2010_service_pack_2
msrcmicrosoft_office_word_viewer
msrcmicrosoft_outlook_2016_for_mac
msrcmicrosoft_word_2007_service_pack_3
msrcmicrosoft_word_2010_service_pack_2
msrcmicrosoft_word_for_mac_2011
msrcword_automation_services_on_microsoft_sharepoint_server_2013_service_pack_1

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat6.8MEDIUM
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.