CVE-2010-3190 - CVE House
Back to Database
Status published Unknown CVE-2010-3190

Untrusted search path vulnerability in the Microsoft Foundation Class (MFC)...

Vulnerability Description

Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory during execution of an MFC application such as AtlTraceTool8.exe (aka ATL MFC Trace Tool), as demonstrated by a directory that contains a TRC, cur, rs, rct, or res file, aka "MFC Insecure Library Loading Vulnerability."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-3190

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

itunes, visual c\+\+, visual studio, visual studio .net
Vulnerable Versions:
12.1.3, 2005, 2008, 2010, 2003

Timeline

Official Publish: August 31st, 2010
Last Modified: May 28th, 2026
Added to House: July 19th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.