Untrusted Search Path Vulnerabilities in Microsoft Groove 2007 SP2
CVE-2010-3146
Currently unrated
Summary
Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 can be exploited by local users to gain unauthorized privileges. This occurs through the exploitation of specific DLL files, such as mso.dll or GroovePerfmon.dll, placed in the working directory. These vulnerabilities are particularly dangerous when users handle Groove vCard (.vcg) or Groove Tool Archive (.gta) files, as attackers can leverage these vectors to load malicious libraries and execute arbitrary code, posing significant risks to system integrity.
References
EPSS Score
48% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved