CVE-2016-0148: Microsoft .NET Framework

High severity, CVSS 7.8. EPSS: 13.9% chance of exploitation in the next 30 days.

Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."

Affected products

  • Microsoft .NET Framework: version 4.6 only; version 4.6.1 only

Published 2016-04-12. Last modified 2026-06-17.