Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1035535 | third party advisory vdb entry |
http://www.securityfocus.com/archive/1/538063/100/0/threaded | mailing list |
http://seclists.org/fulldisclosure/2016/Apr/42 | third party advisory mailing list |
http://packetstormsecurity.com/files/136671/.NET-Framework-4.6-DLL-Hijacking.html | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-041 | vendor advisory |
http://www.zerodayinitiative.com/advisories/ZDI-16-234 | third party advisory |