CVE-2012-0016

Microsoft Expression Design - Privilege Escalation

Title source: llm

Description

Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .xpr or .DESIGN file, aka "Expression Design Insecure Library Loading Vulnerability."

Exploits (1)

exploitdb WORKING POC
rubyremotewindows
https://www.exploit-db.com/exploits/29858

Scores

EPSS 0.4741
EPSS Percentile 97.6%

Classification

Status draft

Affected Products (5)

microsoft/expression_design
microsoft/expression_design
microsoft/expression_design
microsoft/expression_design
microsoft/expression_design

Timeline

Published Mar 13, 2012
Tracked Since Feb 18, 2026