First published: Fri Sep 07 2012(Updated: )
Multiple untrusted search path vulnerabilities in 3D XML Player 6.212.13.12076 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) JT0DevPhase.dll file in the current working directory, as demonstrated by a directory that contains a .3dx file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3ds 3D XML Player | =6.212.13.12076 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4882 is rated as a medium severity vulnerability due to its ability to allow local users to gain elevated privileges.
To fix CVE-2012-4882, ensure that the 3D XML Player is updated to the latest version, which addresses these untrusted search path vulnerabilities.
CVE-2012-4882 affects users of 3D XML Player version 6.212.13.12076 and allows local users to manipulate certain files to exploit the vulnerability.
The potential impacts of CVE-2012-4882 include privilege escalation, which could allow a local user to execute malicious code with elevated permissions.
CVE-2012-4882 can be exploited through the placement of Trojan horse files, specifically dwmapi.dll or JT0DevPhase.dll, in the current working directory.