Vulnerability Description
Untrusted search path vulnerability in the pthread_win32_process_attach_np function in pthreadGC2.dll in Pthreads-win32 2.8.0 allows local users to gain privileges via a Trojan horse quserex.dll file in the current working directory. NOTE: some of these details are obtained from third party information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pthread-Win32 Project | Pthreads-Win32 | 2.8.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/41215Not ApplicableVendor Advisory
- http://www.corelan.be:8800/index.php/2010/08/25/dll-hijacking-kb-2269637-the-unoBroken Link
- http://secunia.com/advisories/41215Not ApplicableVendor Advisory
- http://www.corelan.be:8800/index.php/2010/08/25/dll-hijacking-kb-2269637-the-unoBroken Link
FAQ
What is CVE-2010-5250?
CVE-2010-5250 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Untrusted search path vulnerability in the pthread_win32_process_attach_np function in pthreadGC2.dll in Pthreads-win32 2.8.0 allows local users to gain privileges via a Trojan horse quserex.dll file ...
How severe is CVE-2010-5250?
CVE-2010-5250 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-5250?
Check the references section above for vendor advisories and patch information. Affected products include: Pthread-Win32 Project Pthreads-Win32.