CVE-2010-5196: Medium severity keepass password safe vulnerability
Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dll file in the current working directory, as demonstrated by a directory that contains a .kdbx file. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5196?
CVE-2010-5196 has a moderate severity rating due to its potential for privilege escalation via local exploitation.
How do I fix CVE-2010-5196?
To fix CVE-2010-5196, upgrade KeePass Password Safe to version 2.13 or later.
What versions of KeePass are affected by CVE-2010-5196?
CVE-2010-5196 affects KeePass Password Safe versions prior to 2.13 and version 1.6.
Can CVE-2010-5196 be exploited remotely?
No, CVE-2010-5196 requires local access to the system to exploit the vulnerability.
What type of vulnerability is CVE-2010-5196?
CVE-2010-5196 is classified as an untrusted search path vulnerability, specifically related to DLL hijacking.