Lucene search

K
cveMitreCVE-2010-3148
HistoryAug 27, 2010 - 7:00 p.m.

CVE-2010-3148

2010-08-2719:00:18
mitre
web.nvd.nist.gov
36
cve-2010-3148
microsoft visio
untrusted search path
vulnerability
privilege escalation
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.744

Percentile

98.1%

Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka β€œMicrosoft Visio Insecure Library Loading Vulnerability.”

Affected configurations

Nvd
Node
microsoftvisioMatch2003
VendorProductVersionCPE
microsoftvisio2003cpe:2.3:a:microsoft:visio:2003:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.744

Percentile

98.1%