CVE-2016-0148: High severity microsoft .net framework 4 vulnerability
Published Apr 12, 2016
·Updated
Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."
Affected Software
2 affected components
Microsoft .NET Framework=4.6
Microsoft .NET Framework=4.6.1
Event History
Apr 12, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0148?
CVE-2016-0148 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2016-0148?
To fix CVE-2016-0148, update Microsoft .NET Framework to the latest version that addresses this vulnerability.
3
What software versions are affected by CVE-2016-0148?
CVE-2016-0148 affects Microsoft .NET Framework versions 4.6 and 4.6.1.
4
What type of attack does CVE-2016-0148 enable?
CVE-2016-0148 allows local users to gain elevated privileges by exploiting the mishandling of library loading.
5
Who is at risk from CVE-2016-0148?
Local users with the ability to run crafted applications on systems using the affected .NET Framework versions are at risk from CVE-2016-0148.