First published: Tue Oct 19 2010(Updated: )
Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Flash Player.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Flash Player for Internet Explorer 11 | <=9.0.277.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.16 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.18d60 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.20 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.20.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.28 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.28.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.31 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.31.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.45.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.47.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.48.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.112.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.114.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.115.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.124.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.125.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.151.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.152.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.155.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.159.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.246.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.260.0 | |
Adobe Flash Player for Internet Explorer 11 | =9.0.262.0 | |
Microsoft Windows | ||
Adobe Flash Player for Internet Explorer 11 | <=10.1.92.10 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.0.584 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.12.10 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.12.36 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.15.3 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.22.87 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.32.18 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.42.34 | |
Adobe Flash Player for Internet Explorer 11 | =10.0.45.2 | |
Adobe Flash Player for Internet Explorer 11 | =10.1.52.14.1 | |
Adobe Flash Player for Internet Explorer 11 | =10.1.52.15 | |
Adobe Flash Player for Internet Explorer 11 | =10.1.53.64 | |
Adobe Flash Player for Internet Explorer 11 | =10.1.82.76 | |
Adobe Flash Player for Internet Explorer 11 | =10.1.85.3 | |
Adobe Flash Player for Internet Explorer 11 | =10.1.92.8 | |
Adobe Flash Player for Internet Explorer 11 | =10.1.95.1 | |
Adobe Flash Player for Internet Explorer 11 | =10.1.95.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3976 is classified as a critical vulnerability due to its ability to allow arbitrary code execution through DLL hijacking.
To fix CVE-2010-3976, users should update Adobe Flash Player to the latest version that is not affected by this vulnerability.
CVE-2010-3976 affects Adobe Flash Player versions prior to 9.0.289.0 and 10.x versions before 10.1.102.64 running on Windows.
Yes, CVE-2010-3976 can potentially be exploited by remote attackers if a user opens a malicious file.
CVE-2010-3976 can facilitate DLL hijacking attacks, allowing attackers to execute arbitrary code on the affected machine.