PT-2010-4589 · Microsoft · Windows Xp+2

Muhaimin Dzulfakar

·

Published

2010-08-27

·

Updated

2019-02-26

·

CVE-2010-3144

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP versions SP2 through SP3 Microsoft Windows Server 2003 version SP2
Description The issue allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory. A remote code execution vulnerability exists in the way that the Internet Connection Signup Wizard handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Windows XP versions SP2 through SP3, update to a version that includes a fix for this issue. For Microsoft Windows Server 2003 version SP2, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting the use of the Internet Connection Signup Wizard until a patch is available. Avoid using the affected smmscrpt.dll file in the current working directory until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-3144

Affected Products

Windows
Windows Server 2003
Windows Xp