CVE-2010-3138
Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 27.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability." NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 27.25% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows media player · microsoft/windows xp · bsplayer/bs.player
- Source
- cve@mitre.org
References
- http://osvdb.org/67588
- http://secunia.com/advisories/41114Vendor Advisory
- http://www.exploit-db.com/exploits/14765Exploit
- http://www.exploit-db.com/exploits/14788Exploit
- http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/2190Vendor Advisory
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4956.php
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-014
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7132
- http://osvdb.org/67588
- http://secunia.com/advisories/41114Vendor Advisory
- http://www.exploit-db.com/exploits/14765Exploit
- http://www.exploit-db.com/exploits/14788Exploit
- http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/2190Vendor Advisory
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4956.php
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-014
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7132
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.