CVE-2010-3499: Medium severity f-secure anti-virus vulnerability
F-Secure Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution. NOTE: the researcher indicates that a vendor response was received, stating that "the inability to catch these files are caused by lacking functionality rather than programming errors."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3499?
The severity of CVE-2010-3499 is considered high due to the potential for remote code execution.
How do I fix CVE-2010-3499?
To fix CVE-2010-3499, users should update to the latest version of F-Secure Anti-Virus that addresses this vulnerability.
What type of malware exploits CVE-2010-3499?
CVE-2010-3499 can be exploited by malware that uses hcp:// URLs to execute arbitrary code.
Who is affected by CVE-2010-3499?
Users of F-Secure Anti-Virus are primarily affected by CVE-2010-3499.
When was CVE-2010-3499 disclosed?
CVE-2010-3499 was disclosed in 2010.