CVE-2010-3190
Published Aug 31, 2010
Last updated 4 years ago
Overview
- Description
- Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory during execution of an MFC application such as AtlTraceTool8.exe (aka ATL MFC Trace Tool), as demonstrated by a directory that contains a TRC, cur, rs, rct, or res file, aka "MFC Insecure Library Loading Vulnerability."
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-426
Evaluator
- Comment
- Per: http://cwe.mitre.org/data/definitions/426.html CWE-426: Untrusted Search Path
- Impact
- Per: https://technet.microsoft.com/en-us/security/bulletin/ms11-025 Access Vector: Network per "This is a remote code execution vulnerability"
- Solution
- Per: https://technet.microsoft.com/en-us/security/bulletin/ms11-025 Access Vector: Network per "This is a remote code execution vulnerability"
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apple:itunes:12.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4354E6D0-5AA8-4F1B-BD3B-1B66ABD062A1" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:visual_c\\+\\+:2005:sp1:*:*:redistributable_package:*:*:*", "vulnerable": true, "matchCriteriaId": "619BEBC1-9B3B-47B6-A0FC-E77084D57784" }, { "criteria": "cpe:2.3:a:microsoft:visual_c\\+\\+:2008:sp1:*:*:redistributable_package:*:*:*", "vulnerable": true, "matchCriteriaId": "F5719E28-6122-4BCA-91B7-E9709DA5A891" }, { "criteria": "cpe:2.3:a:microsoft:visual_c\\+\\+:2010:sp1:*:*:redistributable_package:*:*:*", "vulnerable": true, "matchCriteriaId": "A04EBB20-FC22-4482-861F-774853382E8B" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio:2005:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9271AF1C-9B1C-4ADB-9F54-E63EBA2910F9" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio:2008:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AB2C8C4-7E86-4736-9CE4-2E65E4EDBF02" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio:2010:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F4DFC93-9533-4893-B634-0551CDE7D252" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2003:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85959AEB-2FE5-4A25-B298-F8223CE260D6" } ], "operator": "OR" } ] } ]