6.9
CVSSv2

CVE-2010-5239

Published: 07/09/2012 Updated: 07/09/2012
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in DAEMON Tools Lite 4.35.6.0091 and Pro Standard 4.36.0309.0160 allows local users to gain privileges via a Trojan horse mfc80loc.dll file in the current working directory, as demonstrated by a directory that contains a .mds file. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

daemon-tools daemon tools 4.36.0309.0160

daemon-tools daemon tools 4.35.6.0091

Exploits

/* #Demon tool lite DLL Hijacking Exploit (mfc80locdll) #Author : Mohamed Clay #Greetz : linuxacorg && isecur1tyorg && security4arabscom && v4-teamcom && all My Friends #note : EveryOne is happy with DLL Hijacking YooooPiiii!!!! #Tested on: Windows XP #How to use : Place a mds file and mfc80locdll in same fol ...