41109Third-party advisory
http://secunia.com/advisories/41109 CVE-2010-3126
Avast! 5.0.594 - 'mfc90loc.dll' License Files DLL Hijacking
Record summary
CVE-2010-3126 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc90loc.dll that is located in the same folder as an avast license (.avastlic) file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAvast! 5.0.594 - 'mfc90loc.dll' License Files DLL HijackingExploitDB exploitby diwrNot analyzed1 file
References
514743exploit
http://www.exploit-db.com/exploits/14743 ADV-2010-2175vdb entry
http://www.vupen.com/english/advisories/2010/2175 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-3126 oval:org.mitre.oval:def:7193vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7193