CVE-2010-5082
Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 14.94% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows server 2008
- Source
- secure@microsoft.com
References
- http://shinnai.altervista.org/exploits/SH-006-20100914.html
- http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-012
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14446
- http://shinnai.altervista.org/exploits/SH-006-20100914.html
- http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-012
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14446
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.