CVE-2010-3190: High severity Apple iTunes vulnerability
Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory during execution of an MFC application such as AtlTraceTool8.exe (aka ATL MFC Trace Tool), as demonstrated by a directory that contains a TRC, cur, rs, rct, or res file, aka "MFC Insecure Library Loading Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3190?
CVE-2010-3190 is classified as a medium severity vulnerability that allows local users to gain elevated privileges.
How do I fix CVE-2010-3190?
To fix CVE-2010-3190, you should apply the latest security updates provided by Microsoft for the affected software versions.
Which software versions are affected by CVE-2010-3190?
CVE-2010-3190 affects Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1, 2008 SP1, and 2010, as well as Microsoft Visual C++ 2005 SP1, 2008 SP1, and 2010.
What type of vulnerability is CVE-2010-3190?
CVE-2010-3190 is an untrusted search path vulnerability that can be exploited by local users.
Are there any workarounds for CVE-2010-3190?
To mitigate CVE-2010-3190, users can restrict file and folder permissions to limit unauthorized access.