CVE-2010-3146: Critical severity Microsoft Groove vulnerability
Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3146?
CVE-2010-3146 has a CVSS score that typically indicates a medium to high severity due to the potential for privilege escalation.
How do I fix CVE-2010-3146?
To fix CVE-2010-3146, ensure that Microsoft Groove 2007 SP2 is updated to the latest version or apply relevant security patches.
What types of files are involved in CVE-2010-3146?
CVE-2010-3146 involves untrusted search paths related to mso.dll and GroovePerfmon.dll files.
Who is affected by CVE-2010-3146?
Local users of Microsoft Groove 2007 SP2 are primarily affected by CVE-2010-3146.
Can CVE-2010-3146 be exploited remotely?
CVE-2010-3146 cannot be exploited remotely as it requires local access to the vulnerable system.