Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-3138

Опубликовано: 27 авг. 2010
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability." NOTE: some of these details are obtained from third party information.

Комментарий

Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426 - 'Untrusted Search Path Vulnerability'

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:microsoft:windows_media_player:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:bsplayer:bs.player:*:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.43265
Средний

9.3 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability." NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 97%
0.43265
Средний

9.3 Critical

CVSS2

Дефекты

NVD-CWE-Other