CVE-2016-0016
HIGHMicrosoft Windows - Untrusted Search Path DLL Loading Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-0016. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a DLL planting attack in Microsoft Office 2010 on Windows 7 x86 via a crafted OLE object. The attack leverages a vulnerable CLSID to trigger a LoadLibraryW call for 'mfplat.dll' from the current working directory, allowing arbitrary code execution.
Description
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
Exploits (1)
This exploit demonstrates a DLL planting attack in Microsoft Office 2010 on Windows 7 x86 via a crafted OLE object. The attack leverages a vulnerable CLSID to trigger a LoadLibraryW call for 'mfplat.dll' from the current working directory, allowing arbitrary code execution.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H