First published: Fri Aug 27 2010(Updated: )
Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visio Standard | =2003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3148 is considered a high severity vulnerability as it allows local users to gain elevated privileges.
To fix CVE-2010-3148, it is advised to avoid using Microsoft Visio 2003 or to ensure that no untrusted DLLs are placed in the working directory.
CVE-2010-3148 affects local users of Microsoft Visio 2003 SP3 on Windows systems.
CVE-2010-3148 is an untrusted search path vulnerability that allows the execution of malicious DLLs.
CVE-2010-3148 cannot be exploited remotely as it requires local access to the affected system.