Vulnerability Report: GO-2021-0163
standard library- CVE-2016-3958
- Affects: syscall
- Published: Jan 05, 2022
- Modified: May 20, 2024
Untrusted search path vulnerability on Windows related to LoadLibrary allows local users to gain privileges via a malicious DLL in the current working directory.
Affected Packages
-
PathGo VersionsSymbols
-
before go1.5.4, from go1.6.0-0 before go1.6.1
Aliases
References
- https://go.dev/cl/21428
- https://go.googlesource.com/go/+/6a0bb87bd0bf0fdf8ddbd35f77a75ebd412f61b0
- https://go.dev/issue/14959
- https://groups.google.com/g/golang-announce/c/9eqIHqaWvck
- https://vuln.go.dev/ID/GO-2021-0163.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.