First published: Fri Sep 07 2012(Updated: )
Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2) nlsxbe.dll file in the current working directory, as demonstrated by a directory that contains a .vcf, .vcs, or .ics file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Notes | =8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-5251 is classified as a high severity vulnerability due to its potential for local privilege escalation.
To mitigate CVE-2010-5251, ensure that nnoteswc.dll and nlsxbe.dll files are not exposed in user-accessible directories and update to a patched version of IBM Lotus Notes.
CVE-2010-5251 is associated with local privilege escalation attacks using Trojan horse DLL files.
CVE-2010-5251 affects IBM Lotus Notes version 8.5.
The consequences of CVE-2010-5251 include unauthorized access to user privileges and compromise of system security.