9.3
CVSSv2

CVE-2010-3190

Published: 31/08/2010 Updated: 16/11/2020
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory during execution of an MFC application such as AtlTraceTool8.exe (aka ATL MFC Trace Tool), as demonstrated by a directory that contains a TRC, cur, rs, rct, or res file, aka "MFC Insecure Library Loading Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple itunes 12.1.3

microsoft visual c\\+\\+ 2005

microsoft visual c\\+\\+ 2008

microsoft visual c\\+\\+ 2010

microsoft visual studio 2005

microsoft visual studio 2008

microsoft visual studio 2010

microsoft visual studio .net 2003

Vendor Advisories

HP has identified a security vulnerability with the IRIS OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution ...
HP has identified a security vulnerability with the IRIS OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution ...

Recent Articles

It's October 2018, and Microsoft Exchange can be pwned by a plucky eight-year-old... bug
The Register • Shaun Nichols in San Francisco • 09 Oct 2018

Redmond goes retro in latest Patch Tuesday bundle

Microsoft has released the October edition of its monthly security update, addressing a total of 49 CVE-listed bugs. Among the 49 fixes were three issues that have already been publicly disclosed and a fourth that was being targeted in the wild. On top of that, a remote code execution bug in Exchange Server is the resurfacing of a vulnerability first found in 2010. CVE-2010-3190 is a remote code execution bug created by insecure handling of DLL files in applications made with Microsoft Foundatio...