Vulnerabilities > CVE-2010-5239 - Unspecified vulnerability in Daemon-Tools Daemon Tools 4.35.6.0091/4.36.0309.0160

047910
CVSS 6.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
daemon-tools
exploit available

Summary

Untrusted search path vulnerability in DAEMON Tools Lite 4.35.6.0091 and Pro Standard 4.36.0309.0160 allows local users to gain privileges via a Trojan horse mfc80loc.dll file in the current working directory, as demonstrated by a directory that contains a .mds file. NOTE: some of these details are obtained from third party information. Per: http://cwe.mitre.org/data/definitions/426.html 'CWE-426 Untrusted Search Path'

Vulnerable Configurations

Part Description Count
Application
Daemon-Tools
2

Exploit-Db

descriptionDaemon tools lite DLL Hijacking Exploit (mfc80loc.dll). CVE-2010-5239. Local exploit for windows platform
fileexploits/windows/local/14791.c
idEDB-ID:14791
last seen2016-02-01
modified2010-08-25
platformwindows
port
published2010-08-25
reporterMohamed Clay
sourcehttps://www.exploit-db.com/download/14791/
titleDaemon tools lite DLL Hijacking Exploit mfc80loc.dll
typelocal