CVE Database
/

CVE-2010-3190

Back to search

CVE-2010-3190

Published: Aug 31, 2010

Modified: May 28, 2026

PUBLISHED

Description

Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory during execution of an MFC application such as AtlTraceTool8.exe (aka ATL MFC Trace Tool), as demonstrated by a directory that contains a TRC, cur, rs, rct, or res file, aka "MFC Insecure Library Loading Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

41212
third-party-advisory
x_refsource_SECUNIA
TA11-102A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:12457
vdb-entry
signature
x_refsource_OVAL
MS11-025
vendor-advisory
x_refsource_MS
42811
vdb-entry
x_refsource_BID
APPLE-SA-2015-09-16-3
vendor-advisory
x_refsource_APPLE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now