PoC Index

CVE-2010-3131

HIGH 9.3EPSS 22.9%

Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
22.86% chance of exploitation in the next 30 days, 98th percentile
Published
2010-08-26
Updated
2024-08-07

Proof-of-concept exploits (3)

ExploitDB entries (2)

References

Related