First published: Wed Nov 10 2010(Updated: )
Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2007-sp2 | |
Microsoft Office | =2010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3337 has a medium severity rating as it allows local users to gain elevated privileges through a Trojan horse DLL.
To fix CVE-2010-3337, apply the latest security updates provided by Microsoft for Office 2007 SP2 and Office 2010.
CVE-2010-3337 affects Microsoft Office 2007 SP2 and Microsoft Office 2010.
No, CVE-2010-3337 cannot be exploited remotely as it requires local user access to execute the attack.
Exploiting CVE-2010-3337 may allow an attacker to execute malicious code with elevated privileges on the affected system.