Microsoft · Windows Internet Communication Settings · CVE-2010-3140
**Name of the Vulnerable Software and Affected Versions**
Microsoft Windows Internet Communication Settings version not specified
**Description**
The issue concerns an untrusted search path vulnerability that allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks. This can be achieved via a Trojan horse schannel.dll located in the same folder as an ISP file.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.