CVE-2010-3133: Critical severity Wireshark Wireshark vulnerability
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3133?
CVE-2010-3133 is considered a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2010-3133?
To fix CVE-2010-3133, upgrade to a version of Wireshark that is not affected, specifically any version above 1.2.10.
Who is affected by CVE-2010-3133?
CVE-2010-3133 affects local users as well as potentially remote attackers using vulnerable versions of Wireshark.
What types of attacks can CVE-2010-3133 facilitate?
CVE-2010-3133 can facilitate DLL hijacking attacks through the use of a Trojan horse airpcap.dll.
What versions of Wireshark are vulnerable to CVE-2010-3133?
Wireshark versions from 0.8.4 to 1.2.10 are vulnerable to CVE-2010-3133.