---
cve: "CVE-2015-0096"
severity: "LOW"
cvss: 3.1
epss: "71%"
vendor: "n/a"
kev: false
exploited: false
published: "2015-03-11 10:59:22"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T05:07:50+02:00"
---

# CVE-2015-0096

> 3.1 LOW

## Beschreibung

Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading during Windows Explorer access to the icon of a crafted shortcut, aka "DLL Planting Remote Code Execution Vulnerability."

## Exploit-Evidenz

- [EDB-14403 — Microsoft Windows - Automatic .LNK Shortcut File Code Execution](https://www.exploit-db.com/exploits/14403) ✅

## Referenzen

- <http://www.securitytracker.com/id/1031890>
- <https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-020>
- <http://www.securityfocus.com/bid/72894>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-0096) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
