CVE-2016-0041 is a DLL loading vulnerability affecting multiple versions of Microsoft Windows (Vista through Windows 10) and Internet Explorer 10 and 11. This flaw allows a local attacker to gain elevated privileges by tricking a user into running a specially crafted application. Rated with a CVSS score of 7.8 (High), it presents a significant risk due to its potential for complete compromise of confidentiality, integrity, and availability, requiring only low privileges and no user interaction once the malicious application is executed. While not listed on CISA's KEV catalog, exploit code, including a Metasploit module, is publicly available, indicating a practical attack vector. Despite this, there is minimal community discussion or media coverage surrounding this particular CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.