CVE-2011-2016
Last modified
CVE-2011-2016 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability.". EPSS estimates a 8.10% chance of exploitation in the next 30 days.
Description
Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows 7 | All versions | — |
| Microsoft | Windows Server 2008 | All versions | Sp2 |
| Microsoft | Windows Server 2008 | r2 | — |
| Microsoft | Windows Vista | All versions | Sp2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-2016?
How severe is CVE-2011-2016?
How do I fix CVE-2011-2016?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-2010The Microsoft Office Input Method Editor (IME) for Simplifie…
- CVE-2011-2011Use-after-free vulnerability in win32k.sys in the kernel-mod…
- CVE-2011-2012Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, …
- CVE-2011-2013Integer overflow in the TCP/IP implementation in Microsoft W…9.8
- CVE-2011-2014The LDAP over SSL (aka LDAPS) implementation in Active Direc…
- CVE-2011-2015Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2011-2017Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2011-2018The kernel in Microsoft Windows XP SP2 and SP3, Windows Serv…
- CVE-2011-2019Untrusted search path vulnerability in Microsoft Internet Ex…
- CVE-2011-2020Cross-site scripting (XSS) vulnerability in TIBCO iProcess E…
- CVE-2011-2021Session fixation vulnerability in TIBCO iProcess Engine befo…
- CVE-2011-2022The agp_generic_remove_memory function in drivers/char/agp/g…
Are you affected by CVE-2011-2016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
