[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-3190Date: (C)2010-08-31   (M)2024-03-26


Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; and Visual C++ 2005 SP1, 2008 SP1, and 2010 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory during execution of an MFC application such as AtlTraceTool8.exe (aka ATL MFC Trace Tool), as demonstrated by a directory that contains a TRC, cur, rs, rct, or res file, aka "MFC Insecure Library Loading Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECUNIA-41212
BID-42811
APPLE-SA-2015-09-16-3
IAVM:2011-B-0046
MS11-025
TA11-102A
http://www.corelan.be:8800/index.php/2010/08/25/dll-hijacking-kb-2269637-the-unofficial-list/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2010-3190
https://support.apple.com/HT205221
oval:org.mitre.oval:def:12457

CPE    4
cpe:/a:microsoft:visual_studio_.net:2003:sp1
cpe:/a:microsoft:visual_studio:2010
cpe:/a:microsoft:visual_studio:2008:sp1
cpe:/a:apple:itunes:12.1.3
...
CWE    1
CWE-264
OVAL    4
oval:org.secpod.oval:def:27126
oval:org.mitre.oval:def:7378
oval:org.secpod.oval:def:997
oval:org.secpod.oval:def:48147
...

© SecPod Technologies