CVE-2010-3133
Wireshark 0.8.4-1.0.15 and 1.2.0-1.2.10 - Untrusted Search Path DLL Hijacking via Trojan Horse DLL
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-3133. PoCs published by TheLeader.
AI-analyzed exploit summary This exploit leverages DLL hijacking in Wireshark <= 1.2.10 by providing a malicious airpcap.dll that executes arbitrary code (calc.exe) when loaded. It targets Wireshark's default file associations to trigger the payload.
Description
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark.
Exploits (1)
This exploit leverages DLL hijacking in Wireshark <= 1.2.10 by providing a malicious airpcap.dll that executes arbitrary code (calc.exe) when loaded. It targets Wireshark's default file associations to trigger the payload.