PT-2010-4583 · Intel+1 · Indeo Codec+2

Gjoko Krstic

·

Publicado

2010-08-27

·

Atualizado

2018-10-12

·

CVE-2010-3138

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP SP3
Description The issue allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory. This can be demonstrated by access through media players to a directory containing specific file types, such as .avi, .mka, .ra, or .ram files. A remote code execution vulnerability exists in the way the Indeo Codec handles the loading of DLL files, potentially allowing an attacker to take complete control of an affected system, install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Windows XP SP3, consider restricting access to the Indeo Codec or avoiding the use of potentially vulnerable media players until a fix is available. As a temporary workaround, users should be cautious of directories containing .avi, .mka, .ra, or .ram files and avoid using them with media players that could trigger the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-3138

Produtos afetados

Indeo Codec
Windows
Windows Xp