Untrusted search path vulnerability in Go before 1.5.4 and 1.6.x before 1.6.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function.
https://groups.google.com/forum/#%21topic/golang-announce/9eqIHqaWvck
https://go-review.googlesource.com/#/c/21428/
https://github.com/golang/go/issues/14959