Vulnerability Name:

CVE-2010-3138 (CCN-63779)

Assigned:2010-08-23
Published:2010-08-23
Updated:2018-10-12
Summary:Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability."
Note: some of these details are obtained from third party information.
Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426 - 'Untrusted Search Path Vulnerability'
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.3 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2010-3138

Source: OSVDB
Type: UNKNOWN
67588

Source: CCN
Type: SA41114
Microsoft Windows Indeo Filter Insecure Library Loading Vulnerability

Source: SECUNIA
Type: Vendor Advisory
41114

Source: CCN
Type: Microsoft Security Bulletin MS12-014
Vulnerability in Indeo Codec Could Allow Remote Code Execution (2661637)

Source: EXPLOIT-DB
Type: Exploit
14765

Source: EXPLOIT-DB
Type: Exploit
14788

Source: CCN
Type: Microsoft Security Advisory (2269637)
Insecure Library Loading Could Allow Remote Code Execution

Source: CCN
Type: BID-42730
Microsoft Windows Indeo Filter 'iacenc.dll' DLL Loading Arbitrary Code Execution Vulnerability

Source: CERT
Type: US Government Resource
TA12-045A

Source: VUPEN
Type: Vendor Advisory
ADV-2010-2190

Source: MISC
Type: UNKNOWN
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4956.php

Source: MS
Type: UNKNOWN
MS12-014

Source: XF
Type: UNKNOWN
windowsindeofilter-dll-ce(63779)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:7132

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database

Source: EXPLOIT-DB
Type: EXPLOIT
EDB-ID: 14765

Source: EXPLOIT-DB
Type: EXPLOIT
EDB-ID: 14788

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:windows_media_player:*:*:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:bsplayer:bs.player:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:7132
    V
    Indeo Codec Insecure Library Loading Vulnerability
    2012-03-12
    BACK
    microsoft windows media player *
    microsoft windows xp * sp3
    bsplayer bs.player *
    microsoft windows *