PT-2010-4589 · Microsoft · Windows Xp+2

Muhaimin Dzulfakar

·

Publicado

2010-08-27

·

Atualizado

2019-02-26

·

CVE-2010-3144

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP versions SP2 through SP3 Microsoft Windows Server 2003 version SP2
Description The issue allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory. A remote code execution vulnerability exists in the way that the Internet Connection Signup Wizard handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Windows XP versions SP2 through SP3, update to a version that includes a fix for this issue. For Microsoft Windows Server 2003 version SP2, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting the use of the Internet Connection Signup Wizard until a patch is available. Avoid using the affected smmscrpt.dll file in the current working directory until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-3144

Produtos afetados

Windows
Windows Server 2003
Windows Xp