Untrusted Search Path Vulnerabilities in Microsoft Groove 2007 SP2
CVE-2010-3146

Currently unrated

Key Information:

Vendor
Microsoft
Status
Vendor
CVE Published:
27 August 2010

Summary

Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 can be exploited by local users to gain unauthorized privileges. This occurs through the exploitation of specific DLL files, such as mso.dll or GroovePerfmon.dll, placed in the working directory. These vulnerabilities are particularly dangerous when users handle Groove vCard (.vcg) or Groove Tool Archive (.gta) files, as attackers can leverage these vectors to load malicious libraries and execute arbitrary code, posing significant risks to system integrity.

References

EPSS Score

48% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.