CVE-2010-3965: Critical severity microsoft windows media encoder vulnerability
Untrusted search path vulnerability in Windows Media Encoder 9 on Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Windows Media Profile (PRX) file, aka "Insecure Library Loading Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3965?
CVE-2010-3965 is rated as a medium severity vulnerability due to the potential for privilege escalation through a Trojan horse DLL.
How do I fix CVE-2010-3965?
To fix CVE-2010-3965, ensure that you are running an updated version of Windows Media Encoder and apply any applicable security updates from Microsoft.
Who is affected by CVE-2010-3965?
CVE-2010-3965 affects users of Windows Media Encoder 9 on Microsoft Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.
What are the potential impacts of CVE-2010-3965?
The potential impact of CVE-2010-3965 includes unauthorized privilege escalation, which could allow local users to perform actions with elevated permissions.
Is CVE-2010-3965 still relevant today?
While CVE-2010-3965 is an older vulnerability, it may still be relevant for users running unsupported operating systems and software that remain unpatched.