First published: Fri Nov 18 2005(Updated: )
Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | =4.7.1.30 | |
Apple iTunes for Windows | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2938 has a medium severity rating due to its potential to allow local users to gain elevated privileges.
To mitigate CVE-2005-2938, ensure that iTunes is updated to a version that no longer contains the unquoted search path vulnerability.
CVE-2005-2938 affects iTunes versions 4.7.1.30 and 5.0 for Windows.
CVE-2005-2938 is classified as an unquoted Windows search path vulnerability.
CVE-2005-2938 is a local vulnerability, meaning it requires access to the affected system to exploit.