CVE Database
/

CVE-2010-3138

Back to search

CVE-2010-3138

Published: Aug 27, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability." NOTE: some of these details are obtained from third party information.

VendorProductVersions

n/a

n/a

affected
n/a

References

TA12-045A
third-party-advisory
x_refsource_CERT
14765
exploit
x_refsource_EXPLOIT-DB
oval:org.mitre.oval:def:7132
vdb-entry
signature
x_refsource_OVAL
ADV-2010-2190
vdb-entry
x_refsource_VUPEN
67588
vdb-entry
x_refsource_OSVDB
14788
exploit
x_refsource_EXPLOIT-DB
41114
third-party-advisory
x_refsource_SECUNIA
MS12-014
vendor-advisory
x_refsource_MS

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now