CVE-2010-3147

Windows Address Book <6.00.2900.5512 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2010-3147. PoCs published by storm, Beenu Arora, TheLeader.

AI-analyzed exploit summary This exploit demonstrates a DLL hijacking vulnerability in Microsoft Windows Contacts by creating a malicious wab32res.dll that executes arbitrary code (calc.exe) when loaded by affected file types (.contact, .group, .p7c, .vcf, .wab). The DllMain function triggers the payload upon DLL initialization.

Description

Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.

Exploits (3)

exploitdb WORKING POC VERIFIED
by storm · clocalwindows
https://www.exploit-db.com/exploits/14778

This exploit demonstrates a DLL hijacking vulnerability in Microsoft Windows Contacts by creating a malicious wab32res.dll that executes arbitrary code (calc.exe) when loaded by affected file types (.contact, .group, .p7c, .vcf, .wab). The DllMain function triggers the payload upon DLL initialization.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Windows Contacts (Windows Vista SP2)
No auth needed
Prerequisites: Ability to place malicious DLL in a directory with higher search order priority than the legitimate DLL
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Beenu Arora · clocalwindows
https://www.exploit-db.com/exploits/14745

This exploit leverages DLL hijacking in Microsoft Address Book by renaming a malicious DLL to 'wab32res.dll' and placing it in a directory with a '.wab' or '.p7c' file. The DLL executes arbitrary code (e.g., 'calc.exe') when the vulnerable application loads it.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Address Book 6.00.2900.5512
No auth needed
Prerequisites: Ability to place files in a directory where the vulnerable application searches for DLLs
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
by TheLeader · clocalwindows
https://www.exploit-db.com/exploits/14733

This exploit demonstrates a DLL hijacking vulnerability in Microsoft Windows 7's wab.exe by replacing the legitimate wab32res.dll with a malicious one. When a file with specific extensions is opened, the malicious DLL executes arbitrary code (calc.exe in this case).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Windows 7 (6.1.7600 and prior)
No auth needed
Prerequisites: Ability to place a malicious DLL in the same directory as a file with extensions .vcf, .p7c, .group, or .contact · User interaction to open the file
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-348A.html
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/14745/
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41050
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024878
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12352

Scores

EPSS 0.1867
EPSS Percentile 96.9%

Details

Status published
Products (7)
microsoft/outlook_express 6.00.2900.5512
microsoft/windows_2003_server (2 CPE variants)
microsoft/windows_7 (2 CPE variants)
microsoft/windows_server_2003
microsoft/windows_server_2008 (8 CPE variants)
microsoft/windows_vista (3 CPE variants)
microsoft/windows_xp (2 CPE variants)
Published Aug 27, 2010
Tracked Since Feb 18, 2026