Untrusted Search Path Vulnerability in Microsoft Windows Media Encoder
CVE-2010-3965

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
16 December 2010

What is CVE-2010-3965?

This vulnerability occurs in Windows Media Encoder 9 across several Microsoft Windows operating systems. It allows local users to exploit an untrusted search path issue, enabling them to load a malicious DLL from the current working directory. Consequently, this would lead to elevated privileges, which could be leveraged for further malicious actions. The issue is often demonstrated using a directory containing a Windows Media Profile (PRX) file, highlighting the risks associated with insecure library loading.

References

EPSS Score

51% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.