Description
Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.
References (3)
Core 3
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/49449
Patch x_refsource_confirm
http://git.gnome.org/browse/gtk+/commit/modules/engines/ms-windows/xp_theme.c?h=gtk-2-24&id=d6e11a97e318158f5d210a0476870dfe14ed95e6
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/45815
Scores
EPSS
0.0052
EPSS Percentile
66.9%
Details
CWE
CWE-426
Status
published
Products (1)
gnome/gtk
< 2.24.0
Published
Sep 06, 2011
Tracked Since
Feb 18, 2026