CVE-2019-1010100: High severity rufus vulnerability
Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executable installers, portable executables (ALL executables on the web site). The attack vector is: CAPEC-471, CWE-426, CWE-427.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1010100?
The severity of CVE-2019-1010100 is high due to its potential for arbitrary code execution with escalation of privilege.
How do I fix CVE-2019-1010100?
To fix CVE-2019-1010100, update Rufus to version 3.1 or later, which addresses the DLL search order hijacking vulnerability.
What versions of Rufus are affected by CVE-2019-1010100?
Rufus versions 3.0 and earlier are affected by CVE-2019-1010100.
What type of vulnerability is CVE-2019-1010100?
CVE-2019-1010100 is a DLL search order hijacking vulnerability that allows for arbitrary code execution.
Who is affected by CVE-2019-1010100?
Users of Akeo Consulting Rufus 3.0 and earlier are affected by CVE-2019-1010100.