CVE-2016-0018Untrusted Search Path in Microsoft Windows 10

Severity
7.3HIGHNVD
EPSS
6.8%
top 8.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 14

Description

Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages13 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-9pf8-qgf5-cp3v: Microsoft Windows 7 SP1, Windows 8, Windows 82022-05-14

📋Vendor Advisories

1
Microsoft
CVE-2016-0018: Impact: Remote Code Execution Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:N/A;Older Software Release:Exploitation Mor2016-01-12

🕵️Threat Intelligence

3
Talos
Microsoft Patch Tuesday - January 20162016-01-12
Talos
Microsoft Patch Tuesday - January 20162016-01-12
Zscaler
Zscaler found Multiple Security Vulnerabilities | 01-12-2016