CVE-2010-1795: Critical severity itunes vulnerability
Untrusted search path vulnerability in Apple iTunes before 9.1, when running on Windows 7, Vista, and XP, allows local users and possibly remote attackers to gain privileges via a Trojan horse DLL in the current working directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1795?
CVE-2010-1795 is classified as a medium severity vulnerability, allowing local users or potentially remote attackers to gain elevated privileges.
How do I fix CVE-2010-1795?
To mitigate CVE-2010-1795, upgrade to a newer version of Apple iTunes that is patched against this vulnerability.
What systems are affected by CVE-2010-1795?
CVE-2010-1795 affects various versions of Apple iTunes running on Windows operating systems including Windows XP, Vista, and 7.
What type of vulnerability is CVE-2010-1795?
CVE-2010-1795 is an untrusted search path vulnerability due to improper handling of DLL files.
Can CVE-2010-1795 be exploited remotely?
While CVE-2010-1795 primarily allows for local user exploitation, there is a potential for remote exploitation if an attacker has a way to execute code on the system.