9.3
CVSSv2

CVE-2010-3131

Published: 26/08/2010 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Mozilla Firefox prior to 3.5.12 and 3.6.x prior to 3.6.9, Thunderbird prior to 3.0.7 and 3.1.x prior to 3.1.3, and SeaMonkey prior to 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.6.4

mozilla firefox 3.6.6

mozilla firefox 3.6.8

mozilla firefox 3.6.7

mozilla firefox 3.6

mozilla firefox 3.6.2

mozilla firefox 3.6.3

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.4

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.7

mozilla seamonkey 1.5.0.9

mozilla seamonkey 2.0

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.8

mozilla seamonkey 1.1.9

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.2

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.8

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0a1pre

mozilla seamonkey 2.0.5

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.5

mozilla seamonkey 1.5.0.10

mozilla seamonkey 1.5.0.8

mozilla seamonkey

mozilla thunderbird 3.1

mozilla thunderbird 3.1.1

mozilla thunderbird 3.0.4

mozilla thunderbird 3.0

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0.0.4

mozilla thunderbird 3.1.2

mozilla thunderbird

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.7

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.23

mozilla thunderbird 2.0.0.6

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.0.3

mozilla thunderbird 1.0.4

mozilla thunderbird 0.7.1

mozilla thunderbird 0.8

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.2

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.18

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.5

mozilla thunderbird 1.0.5

mozilla thunderbird 1.0

mozilla thunderbird 0.9

mozilla thunderbird 0.1

mozilla thunderbird 0.2

mozilla thunderbird 2.0.0.8

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.9

mozilla thunderbird 1.5.1

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.0.8

mozilla thunderbird 1.0.2

mozilla thunderbird 0.7.3

mozilla thunderbird 0.7

mozilla thunderbird 0.3

mozilla thunderbird 0.4

mozilla thunderbird 3.0.5

mozilla thunderbird 3.0.3

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.17

mozilla thunderbird 1.5.0.8

mozilla thunderbird 1.5.2

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.7

mozilla thunderbird 1.0.1

mozilla thunderbird 0.7.2

mozilla thunderbird 0.5

mozilla thunderbird 0.6

mozilla firefox 3.5.1

mozilla firefox 3.5.2

mozilla firefox 3.5.3

mozilla firefox 3.5.9

mozilla firefox 3.5.8

mozilla firefox 3.0.12

mozilla firefox 3.0.11

mozilla firefox 3.0.10

mozilla firefox 3.0.3

mozilla firefox 3.5.6

mozilla firefox 3.5.7

mozilla firefox 3.0.16

mozilla firefox 3.0.15

mozilla firefox 3.0.7

mozilla firefox 3.0.6

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.3

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.11

mozilla firefox 1.5.1

mozilla firefox 1.5.2

mozilla firefox 1.5.0.8

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 3.5.10

mozilla firefox

mozilla firefox 3.0.14

mozilla firefox 3.0.13

mozilla firefox 3.0.5

mozilla firefox 3.0.4

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.7

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.1

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.6

mozilla firefox 1.0.1

mozilla firefox 1.0

mozilla firefox 1.0.8

mozilla firefox 3.0.2

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.9

mozilla firefox 2.0

mozilla firefox 2.0.0.18

mozilla firefox 1.5

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.10

mozilla firefox 1.5.0.7

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 3.5.4

mozilla firefox 3.5.5

mozilla firefox 3.5

mozilla firefox 3.0.17

mozilla firefox 3.0.9

mozilla firefox 3.0.8

mozilla firefox 3.0.1

mozilla firefox 3.0

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.2

mozilla firefox 1.5.3

mozilla firefox 1.5.4

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 1.0.5

mozilla firefox 1.0.4

Vendor Advisories

Mozilla Foundation Security Advisory 2010-52 Windows XP DLL loading vulnerability Announced September 7, 2010 Reporter Haifei Li, Acros Security Impact Critical Products Firefox, SeaMonkey, Thunderbird Fixed in ...

Exploits

/* Exploit Title: Mozilla Thunderbird DLL Hijacking Exploit ( dwmapidll ) Date: 26/08/2010 Author: h4ck3r#47 twittercom/hxteam Version: Latest Mozilla Thunderbird 312 Tested on: Windows XP SP3 The code is based on the exploit from "TheLeader" Vulnerable extensions: eml html */ #include <windowsh> #define DLLIMPORT __declspec ...
/* Exploit Title: Firefox <= 368 DLL Hijacking Exploit [dwmapidll] Date: August 24, 2010 Author: Glafkos Charalambous (glafkos[@]astalavista[dot]com) Version: Latest Firefox v368 Tested on: Windows XP SP3 En Vulnerable extensions: htm html jtx mfp Greetz: Astalavista, OffSEC, Exploit-DB */ #include <windowsh> #define DllExport ...