CVE-2011-3360

Wireshark <1.4.9, <1.6.2 - Privilege Escalation

Title source: llm

Description

Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18125
metasploit WORKING POC EXCELLENT
by Haifei Li, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/wireshark_lua.rb

Scores

EPSS 0.6577
EPSS Percentile 98.5%

Details

Status published
Products (11)
wireshark/wireshark 1.4.0
wireshark/wireshark 1.4.1
wireshark/wireshark 1.4.2
wireshark/wireshark 1.4.3
wireshark/wireshark 1.4.4
wireshark/wireshark 1.4.5
wireshark/wireshark 1.4.6
wireshark/wireshark 1.4.7
wireshark/wireshark 1.4.8
wireshark/wireshark 1.6.0
... and 1 more
Published Sep 20, 2011
Tracked Since Feb 18, 2026