CVE-2016-0148
published 2016-04-12CVE-2016-0148: Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework…
PriorityP350high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
13.92%
96.1th percentile
Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| msrc | microsoft_net_framework_4.6_4.6.1_on_windows_7_for_32-bit_systems_service_pack | — | — |
| msrc | microsoft_net_framework_4.6_4.6.1_on_windows_7_for_x64-based_systems_service_pa | — | — |
| msrc | microsoft_net_framework_4.6_4.6.1_on_windows_server_2008_r2_for_x64-based_syste | — | — |
| msrc | microsoft_net_framework_4.6_on_windows_server_2008_for_32-bit_systems_service_p | — | — |
| msrc | microsoft_net_framework_4.6_on_windows_server_2008_for_x64-based_systems_servic | — | — |
| msrc | microsoft_net_framework_4.6_on_windows_vista_service_pack_2 | — | — |
| msrc | microsoft_net_framework_4.6_on_windows_vista_x64_edition_service_pack_2 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c286-rjqc-8qxh: Microsoft
ghsa_unreviewed·2022-05-14
CVE-2016-0148 [HIGH] GHSA-c286-rjqc-8qxh: Microsoft
Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."
Microsoft
.NET Framework Remote Code Execution Vulnerability
vendor_msrc·2016-04-12·CVSS 7.8
CVE-2016-0148 [HIGH] .NET Framework Remote Code Execution Vulnerability
.NET Framework Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Microsoft .NET Framework fails to properly validate input before loading libraries. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
To exploit the vulnerability, an attacker would first need to access the local system with the ability to execute a malicious application.
The security update addresses the vulnerability by correcting how .NET validates input on
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - April 2016
blogs_talos·2016-04-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - April 2016
## Microsoft Patch Tuesday - April 2016
Bulletins MS16-037 through MS16-040 and bulletins MS16-042, MS16-050 are rated as critical in this month's release.
MS16-037 is related to six vulnerabilities in Internet Explorer. The most severe vulnerabilities allow an attacker to craft a website that executes arbitrary code on the victim's device due to the memory corruption vulnerabilities in the browser. The attacker would be limited to executing code with same administrative rights as the current user, but with many users having full administrator rights, an attacker could use this to take full control of a device. To exploit the vulnerability the attacker must get the victim to view attacker controlled content. Previously, this has not proved a major limitation for attackers. Attackers have
Talos
Microsoft Patch Tuesday - April 2016
blogs_talos·2016-04-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - April 2016
Bulletins MS16-037 through MS16-040 and bulletins MS16-042, MS16-050 are rated as critical in this month's release.
MS16-037 is related to six vulnerabilities in Internet Explorer. The most severe vulnerabilities allow an attacker to craft a website that executes arbitrary code on the victim's device due to the memory corruption vulnerabilities in the browser. The attacker would be limited to executing code with same administrative rights as the current user, but with many users having full administrator rights, an attacker could use this to take full control of a device. To exploit the vulnerability the attacker must get the victim to view attacker controlled content. Previously, this has not proved a major limitation for attackers. Attackers have proved adept at sending spam messages, c
http://packetstormsecurity.com/files/136671/.NET-Framework-4.6-DLL-Hijacking.htmlhttp://seclists.org/fulldisclosure/2016/Apr/42http://www.securityfocus.com/archive/1/538063/100/0/threadedhttp://www.securitytracker.com/id/1035535http://www.zerodayinitiative.com/advisories/ZDI-16-234https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-041http://packetstormsecurity.com/files/136671/.NET-Framework-4.6-DLL-Hijacking.htmlhttp://seclists.org/fulldisclosure/2016/Apr/42http://www.securityfocus.com/archive/1/538063/100/0/threadedhttp://www.securitytracker.com/id/1035535http://www.zerodayinitiative.com/advisories/ZDI-16-234https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-041
2016-04-12
Published