CVE-2010-1819

Apple QuickTime < 7.6.8 - Untrusted Search Path Vulnerability via Trojan Horse DLL

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 7.6.8 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) CoreVideo.dll, (2) CoreGraphics.dll, or (3) CoreAudioToolbox.dll that is located in the same folder as a .pic image file.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4339
Vendor Advisory x_refsource_misc
http://www.fortiguard.com/advisory/FGA-2010-46/
Patch, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010/Sep/msg00003.html

Scores

EPSS 0.0470
EPSS Percentile 90.9%

Details

Status published
Products (6)
apple/quicktime 7.6.0
apple/quicktime 7.6.1
apple/quicktime 7.6.2
apple/quicktime 7.6.5
apple/quicktime 7.6.6
apple/quicktime < 7.6.7
Published Dec 27, 2013
Tracked Since Feb 18, 2026