Vulnerability record · CVE-2016-0041 · published 10 February 2016
CVE-2016-0041: Windows and IE DLL loading flaw allows local privilege escalation
Microsoft · Internet Explorer
Microsoft Windows and Internet Explorer mishandle DLL loading, letting a local user load a crafted DLL and gain elevated privileges. The flaw spans many Windows versions and IE 10/11, so any unpatched host running those builds is exposed to a local attacker.
Description
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation with full system impact and a very high EPSS score, though no confirmed in-the-wild exploitation is recorded.
What it is
Microsoft Windows and Internet Explorer mishandle DLL loading, letting a local user load a crafted DLL and gain elevated privileges. The flaw spans many Windows versions and IE 10/11, so any unpatched host running those builds is exposed to a local attacker.
Impact
An attacker who can run code on the machine gains full control of the affected system, including confidentiality, integrity and availability of all data and processes.
Attack surface
Reached locally by running a crafted application on the target host; the CVSS vector shows local access, low privileges and no user interaction, so no remote or authenticated network path is required.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.829, 99.7th percentile), indicating strong likelihood of exploitation activity.
What to do
- Apply the Microsoft security updates MS16-009 and MS16-014 to all affected Windows and Internet Explorer builds.
- Retire or isolate unsupported platforms such as Windows Vista SP2 and Windows Server 2008 SP2 that cannot be patched.
- Restrict local interactive logon and application execution rights to trusted users to reduce the pool of potential local attackers.
- Enable Safe DLL search mode and audit DLL search paths for writable directories that could host a planted DLL.
Detection
- Monitor for unexpected DLLs loaded from user-writable paths by privileged processes.
- Alert on process creation where a low-privilege user launches binaries that subsequently load DLLs from non-standard directories.
- Audit Windows event logs for privilege escalation or token elevation anomalies on affected hosts.
- Track patch state of MS16-009 and MS16-014 across the estate and flag unpatched endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0041 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0041), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.