Aloha, *python-3.5.2.exe* loads and executes fwbase.dll from its "application directory". For software downloaded with a web browser the applicationdirectory is typically the user's "Downloads" directory: see < https://insights.sei.cmu.edu/cert/2008/09/carpet-bombing-and-directory-poisoning.html >, and for "prior art" about this well-known and well-documented vulnerability. If an attacker places one of the above named DLL in the user's "Downloads" directory (for example per "drive-by download" or "social engineering") this vulnerability becomes a remote code execution. Proof of concept/demonstration: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 1. Create malicious dll file and save it as fwbase.dll in your "Downloads" directory. 2. Download Windows x86 executable installer from https://www.python.org/downloads/release/python-352/ and save it in your "Downloads" directory. 3. Execute python-3.5.2.exe from your "Downloads" directory. 4. Malicious dll file gets executed. Chao!! Himanshu Mehta