CVE-2010-3976: Critical severity macromedia flash player vulnerability
Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Flash Player.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3976?
CVE-2010-3976 is classified as a critical vulnerability due to its ability to allow arbitrary code execution through DLL hijacking.
How do I fix CVE-2010-3976?
To fix CVE-2010-3976, users should update Adobe Flash Player to the latest version that is not affected by this vulnerability.
What systems are affected by CVE-2010-3976?
CVE-2010-3976 affects Adobe Flash Player versions prior to 9.0.289.0 and 10.x versions before 10.1.102.64 running on Windows.
Can CVE-2010-3976 be exploited remotely?
Yes, CVE-2010-3976 can potentially be exploited by remote attackers if a user opens a malicious file.
What type of attacks can CVE-2010-3976 facilitate?
CVE-2010-3976 can facilitate DLL hijacking attacks, allowing attackers to execute arbitrary code on the affected machine.