Vulnerabilities > CVE-2010-3148 - Unspecified vulnerability in Microsoft Visio 2003
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Microsoft Visio 2003 DLL Hijacking Exploit (mfc71enu.dll). CVE-2010-3148. Local exploit for windows platform |
file | exploits/windows/local/14744.c |
id | EDB-ID:14744 |
last seen | 2016-02-01 |
modified | 2010-08-25 |
platform | windows |
port | |
published | 2010-08-25 |
reporter | Beenu Arora |
source | https://www.exploit-db.com/download/14744/ |
title | Microsoft Visio 2003 DLL Hijacking Exploit mfc71enu.dll |
type | local |
Msbulletin
bulletin_id | MS11-055 |
bulletin_url | |
date | 2011-07-12T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 2560847 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in Microsoft Visio Could Allow Remote Code Execution |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS11-055.NASL |
description | The remote host contains a version of Microsoft Visio that is affected by an insecure library loading vulnerability. A remote attacker could exploit this by tricking a user into opening a specially crafted Microsoft Visio file, resulting in arbitrary code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 55571 |
published | 2011-07-12 |
reporter | This script is Copyright (C) 2011-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/55571 |
title | MS11-055: Vulnerability in Microsoft Visio Could Allow Remote Code Execution (2560847) |
code |
|
Oval
accepted | 2013-02-11T04:03:45.086-05:00 | ||||||||||||
class | vulnerability | ||||||||||||
contributors |
| ||||||||||||
definition_extensions |
| ||||||||||||
description | Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability." | ||||||||||||
family | windows | ||||||||||||
id | oval:org.mitre.oval:def:7122 | ||||||||||||
status | accepted | ||||||||||||
submitted | 2010-10-08T04:21:55 | ||||||||||||
title | Untrusted search path vulnerability in Microsoft Visio 2003 | ||||||||||||
version | 10 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 42681 CVE ID: CVE-2010-3148 Microsoft Visio是Windows 操作系统下运行的流程图软件,它现在是Microsoft Office软件的一个部分。 Microsoft Visio在实现上存在不安全库加载漏洞,远程攻击者可利用此漏洞控制受影响系统。 此漏洞源于以不安全的方式加载应用程序库(例如mfc71enu.dll和mfc71loc.dll),通过诱使用户打开位于远程WebDAV或SMB共享上的Microsoft Visio Stencil (".vss")文件,造成加载任意库。 Microsoft Visio 2003 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS11-055)以及相应补丁: MS11-055:Vulnerability in Microsoft Visio Could Allow Remote Code Execution (2560847) 链接:http://www.microsoft.com/technet/security/bulletin/MS11-055.asp |
id | SSV:20717 |
last seen | 2017-11-19 |
modified | 2011-07-14 |
published | 2011-07-14 |
reporter | Root |
title | Microsoft Visio 2003 "mfc71enu.dll" DLL加载远程代码执行漏洞(MS11-055) |
References
- http://www.exploit-db.com/exploits/14744/
- http://www.exploit-db.com/exploits/14744/
- http://www.us-cert.gov/cas/techalerts/TA11-193A.html
- http://www.us-cert.gov/cas/techalerts/TA11-193A.html
- http://www.vupen.com/english/advisories/2010/2192
- http://www.vupen.com/english/advisories/2010/2192
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-055
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-055
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7122
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7122