Lucene search

K
cveMitreCVE-2010-5249
HistorySep 07, 2012 - 10:32 a.m.

CVE-2010-5249

2012-09-0710:32:22
mitre
web.nvd.nist.gov
31
sophos
free encryption
safeguard privatecrypto
vulnerability
cve-2010-5249
untrusted search path
local users
privileges
pcrypt0406.dll
directory

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

24.5%

Untrusted search path vulnerability in Sophos Free Encryption 2.40.1.1 and Sophos SafeGuard PrivateCrypto 2.40.1.2 allows local users to gain privileges via a Trojan horse pcrypt0406.dll file in the current working directory, as demonstrated by a directory that contains a .uti file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected configurations

Nvd
Node
sophosfree_encryptionMatch2.40.1.1
OR
sophossafeguard_privatecryptoMatch2.40.1.2
VendorProductVersionCPE
sophosfree_encryption2.40.1.1cpe:2.3:a:sophos:free_encryption:2.40.1.1:*:*:*:*:*:*:*
sophossafeguard_privatecrypto2.40.1.2cpe:2.3:a:sophos:safeguard_privatecrypto:2.40.1.2:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

24.5%

Related for CVE-2010-5249