Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-0041.
AI-analyzed exploit summary This Metasploit module exploits multiple DLL side-loading vulnerabilities in various COM components by embedding a malicious OLE object in a PowerPoint file. When opened, the file triggers the loading of a malicious DLL from the current directory, leading to arbitrary code execution.
Description
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
Exploits (1)
This Metasploit module exploits multiple DLL side-loading vulnerabilities in various COM components by embedding a malicious OLE object in a PowerPoint file. When opened, the file triggers the loading of a malicious DLL from the current directory, leading to arbitrary code execution.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H