DLL Loading Privilege Escalation in Microsoft Windows Products
CVE-2016-0018
7.3HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 13 January 2016
Summary
The vulnerability occurs when Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 improperly handle the loading of Dynamic Link Libraries (DLLs). This flaw can be exploited by local users who craft malicious applications, leading to unauthorized privilege escalation within the affected operating systems.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved