Description
Untrusted search path vulnerability in Apple iTunes before 9.1, when running on Windows 7, Vista, and XP, allows local users and possibly remote attackers to gain privileges via a Trojan horse DLL in the current working directory.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/61223
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4105
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7217
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/42541
Various Sources x_refsource_misc
http://www.acrossecurity.com/aspr/ASPR-2010-08-18-1-PUB.txt
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/513190/100/0/threaded
Scores
EPSS
0.0304
EPSS Percentile
86.2%
Details
Status
published
Products (50)
apple/itunes
1.0
apple/itunes
1.1.1
apple/itunes
1.1.2
apple/itunes
2.0.0
apple/itunes
2.0.1
apple/itunes
2.0.2
apple/itunes
2.0.3
apple/itunes
2.0.4
apple/itunes
3.0.0
apple/itunes
3.0.1
... and 40 more
Published
Aug 20, 2010
Tracked Since
Feb 18, 2026