CVE-2012-4882: Medium severity 3DS 3d Xml Player vulnerability
Multiple untrusted search path vulnerabilities in 3D XML Player 6.212.13.12076 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) JT0DevPhase.dll file in the current working directory, as demonstrated by a directory that contains a .3dx file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4882?
CVE-2012-4882 is rated as a medium severity vulnerability due to its ability to allow local users to gain elevated privileges.
How do I fix CVE-2012-4882?
To fix CVE-2012-4882, ensure that the 3D XML Player is updated to the latest version, which addresses these untrusted search path vulnerabilities.
Who is affected by CVE-2012-4882?
CVE-2012-4882 affects users of 3D XML Player version 6.212.13.12076 and allows local users to manipulate certain files to exploit the vulnerability.
What are the potential impacts of CVE-2012-4882?
The potential impacts of CVE-2012-4882 include privilege escalation, which could allow a local user to execute malicious code with elevated permissions.
What specific files can exploit CVE-2012-4882?
CVE-2012-4882 can be exploited through the placement of Trojan horse files, specifically dwmapi.dll or JT0DevPhase.dll, in the current working directory.