PT-2012-1460 · Unknown · Pthreads-Win32

Published

2012-09-07

·

Updated

2022-09-06

·

CVE-2010-5250

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pthreads-win32 version 2.8.0
Description The issue is related to an untrusted search path vulnerability in the pthread win32 process attach np function in pthreadGC2.dll. This allows local users to gain privileges via a Trojan horse quserex.dll file in the current working directory.
Recommendations For Pthreads-win32 version 2.8.0, consider restricting access to the pthread win32 process attach np function until a patch is available. As a temporary workaround, avoid using the pthreadGC2.dll in sensitive operations to minimize the risk of exploitation.

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2010-5250

Affected Products

Pthreads-Win32