PT-2010-4589 · Microsoft · Windows Xp+2
Muhaimin Dzulfakar
·
Published
2010-08-27
·
Updated
2019-02-26
·
CVE-2010-3144
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP versions SP2 through SP3
Microsoft Windows Server 2003 version SP2
Description
The issue allows local users to gain privileges via a Trojan horse
smmscrpt.dll file in the current working directory. A remote code execution vulnerability exists in the way that the Internet Connection Signup Wizard handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights.Recommendations
For Microsoft Windows XP versions SP2 through SP3, update to a version that includes a fix for this issue.
For Microsoft Windows Server 2003 version SP2, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting the use of the Internet Connection Signup Wizard until a patch is available.
Avoid using the affected
smmscrpt.dll file in the current working directory until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Server 2003
Windows Xp