CVE-2016-0179

HIGH

Windows Shell - Remote Code Execution via Crafted Web Site

Title source: llm
STIX 2.1

Description

Windows Shell in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Shell Remote Code Execution Vulnerability."

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/89868
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035825

Scores

CVSS v3 7.8
EPSS 0.2419
EPSS Percentile 97.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (5)
microsoft/windows_10
microsoft/windows_10 1511
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_2012 r2
Published May 11, 2016
Tracked Since Feb 18, 2026