CVE-2010-3966
Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS file, or a WPOST file, aka "BranchCache Insecure Library Loading Vulnerability."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 13.19% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 7 · microsoft/windows server 2008
- Source
- secure@microsoft.com
References
- http://osvdb.org/69816
- http://secunia.com/advisories/42609Vendor Advisory
- http://www.securityfocus.com/bid/45295
- http://www.securitytracker.com/id?1024877
- http://www.us-cert.gov/cas/techalerts/TA10-348A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/3218Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-095
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12163
- http://osvdb.org/69816
- http://secunia.com/advisories/42609Vendor Advisory
- http://www.securityfocus.com/bid/45295
- http://www.securitytracker.com/id?1024877
- http://www.us-cert.gov/cas/techalerts/TA10-348A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2010/3218Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-095
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12163
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.