CVE-2010-3145

Microsoft BitLocker Drive Encryption API - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-3145. PoCs published by Beenu Arora.

AI-analyzed exploit summary This exploit leverages DLL hijacking in Microsoft Vista BitLocker Drive Encryption by renaming a malicious DLL to 'fveapi.dll' and placing it in a directory with a '.wbcat' file. The DLL executes arbitrary code (calc.exe) when the vulnerable application loads it.

Description

Untrusted search path vulnerability in the BitLocker Drive Encryption API, as used in sdclt.exe in Backup Manager in Microsoft Windows Vista SP1 and SP2, allows local users to gain privileges via a Trojan horse fveapi.dll file in the current working directory, as demonstrated by a directory that contains a Windows Backup Catalog (.wbcat) file, aka "Backup Manager Insecure Library Loading Vulnerability."

Exploits (1)

exploitdb WORKING POC
by Beenu Arora · textlocalwindows
https://www.exploit-db.com/exploits/14751

This exploit leverages DLL hijacking in Microsoft Vista BitLocker Drive Encryption by renaming a malicious DLL to 'fveapi.dll' and placing it in a directory with a '.wbcat' file. The DLL executes arbitrary code (calc.exe) when the vulnerable application loads it.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Vista BitLocker Drive Encryption
No auth needed
Prerequisites: Ability to place a malicious DLL and a '.wbcat' file in a directory where the vulnerable application searches for DLLs
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/14751/
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0074
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024948
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-011A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12273

Scores

EPSS 0.1094
EPSS Percentile 95.3%

Details

Status published
Products (1)
microsoft/windows_vista (2 CPE variants)
Published Aug 27, 2010
Tracked Since Feb 18, 2026