CVE-2010-3144

Microsoft Windows XP/SP3-Server 2003 SP2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Beenu Arora · textlocalwindows
https://www.exploit-db.com/exploits/14754

References (5)

Core 5
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-348A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024879
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11993
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/14754/

Scores

EPSS 0.1228
EPSS Percentile 93.9%

Details

Status published
Products (2)
microsoft/windows_server_2003
microsoft/windows_xp (2 CPE variants)
Published Aug 27, 2010
Tracked Since Feb 18, 2026