CVE-2012-3004: Medium severity RealFlex RealWin vulnerability
Multiple untrusted search path vulnerabilities in RealFlex RealWin before 2.1.13, FlexView before 3.1.86, and RealWinDemo before 2.1.13 allow local users to gain privileges via a Trojan horse (1) realwin.dll or (2) keyhook.dll file in the current working directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3004?
CVE-2012-3004 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2012-3004?
To fix CVE-2012-3004, upgrade to RealFlex RealWin version 2.1.13 or later, FlexView version 3.1.86 or later, or RealWinDemo version 2.1.13 or later.
What are the affected versions in CVE-2012-3004?
Affected versions include RealWin versions prior to 2.1.13, FlexView versions prior to 3.1.86, and RealWinDemo versions prior to 2.1.13.
What type of vulnerability is CVE-2012-3004?
CVE-2012-3004 is categorized as an untrusted search path vulnerability allowing local users to exploit privileges.
Who can exploit CVE-2012-3004?
Local users can exploit CVE-2012-3004 by placing a Trojan horse DLL file in the current working directory.