First published: Thu Aug 26 2010(Updated: )
Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc90loc.dll that is located in the same folder as an avast license (.avastlic) file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast Free Antivirus | <=5.0.594 | |
Avast Antivirus | <=5.0.594 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3126 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2010-3126, upgrade to avast! Free Antivirus version 5.0.595 or later immediately.
CVE-2010-3126 affects users of avast! Free Antivirus versions 5.0.594 and earlier.
CVE-2010-3126 can enable local users and remote attackers to execute arbitrary code through DLL hijacking.
CVE-2010-3126 presents an untrusted search path vulnerability that allows exploitation via a malicious mfc90loc.dll file.