Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-007 | patch vendor advisory |
http://www.securitytracker.com/id/1034661 | vdb entry third party advisory |