Hi @ll, the executable installer for Microsoft's Visual Studio 2015 Community Edition, available from , is vulnerable to DLL hijacking: on a fully patched Windows 7 SP1 it loads the following DLLs from its "application directory" instead of Windows' "system directory": Version.dll, AppHelp.dll, NTMARTA.dll, CryptSP.dll, RPCRTRemote.dll Additionally it loads API-MS-Win-Downlevel-ShlWAPI-L2-1-0.dll from the PATH. See or and for a similar vulnerability. stay tuned Stefan Kanthak Timeline: ~~~~~~~~~ 2016-06-01 sent vulnerability report to vendor plus US-CERT NO RESPONSE from vendor, not even an acknowledgement of receipt 2016-06-07 US-CERT tells me that Microsoft informed them that they won't act on this report still no response from vendor 2016-07-01 report published