Local Code Execution Vulnerability in Nullsoft Winamp by Nullsoft
CVE-2010-3137

Currently unrated

Key Information:

Vendor

Nullsoft

Status
Vendor
CVE Published:
26 August 2010

What is CVE-2010-3137?

An untrusted search path vulnerability exists in Nullsoft Winamp, allowing local users or potentially remote attackers to execute arbitrary code. This risk is facilitated by the improper handling of the wnaspi32.dll file, which may be exploited if placed in the same directory as certain media files. This creates a vector for DLL hijacking attacks, where malicious users can compromise the application’s operation and execute unauthorized code on the affected system.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.