Local Code Execution Vulnerability in Nullsoft Winamp by Nullsoft
CVE-2010-3137

Currently unrated

Key Information:

Vendor

Nullsoft

Status
Vendor
CVE Published:
26 August 2010

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2010-3137?

An untrusted search path vulnerability exists in Nullsoft Winamp, allowing local users or potentially remote attackers to execute arbitrary code. This risk is facilitated by the improper handling of the wnaspi32.dll file, which may be exploited if placed in the same directory as certain media files. This creates a vector for DLL hijacking attacks, where malicious users can compromise the application’s operation and execute unauthorized code on the affected system.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.