GHSA-4qmw-vcgw-w2vh · Severity: high — Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft...
Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory during execution of an MFC application such as AtlTraceTool8.exe (aka ATL MFC Trace Tool), as demonstrated by a directory that contains a TRC, cur, rs, rct, or res file, aka "MFC Insecure Library Loading Vulnerability."
Conclusion & alert: CVE-2010-3190 is rated High Risk (66.6/100): CVSS High severity, with high exploitation likelihood (EPSS 39.23%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +1.30% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-05 | 37.92% | 39.23% | +1.30% |
| 2 | 2026-05-31 | 39.23% | 37.92% | -1.30% |
| 3 | 2026-05-29 | — | 39.23% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 9.3 | 2.0 | HIGH |
|
8.6 | 10.0 | [email protected] |
GHSA-4qmw-vcgw-w2vh · Severity: high — Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft...
: Per: https://technet.microsoft.com/en-us/security/bulletin/ms11-025 Access Vector: Network per "This is a remote code execution vulnerability"
: Per: http://cwe.mitre.org/data/definitions/426.html CWE-426: Untrusted Search Path
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apple | itunes | 12.1.3 | cpe:2.3:a:apple:itunes:12.1.3:*:*:*:*:*:*:* |
| microsoft | visual_c\+\+ | 2005 | cpe:2.3:a:microsoft:visual_c\+\+:2005:sp1:*:*:redistributable_package:*:*:* |
| microsoft | visual_c\+\+ | 2008 | cpe:2.3:a:microsoft:visual_c\+\+:2008:sp1:*:*:redistributable_package:*:*:* |
| microsoft | visual_c\+\+ | 2010 | cpe:2.3:a:microsoft:visual_c\+\+:2010:sp1:*:*:redistributable_package:*:*:* |
| microsoft | visual_studio | 2005 | cpe:2.3:a:microsoft:visual_studio:2005:sp1:*:*:*:*:*:* |
| microsoft | visual_studio | 2008 | cpe:2.3:a:microsoft:visual_studio:2008:sp1:*:*:*:*:*:* |
| microsoft | visual_studio | 2010 | cpe:2.3:a:microsoft:visual_studio:2010:-:*:*:*:*:*:* |
| microsoft | visual_studio_.net | 2003 | cpe:2.3:a:microsoft:visual_studio_.net:2003:sp1:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.html | Mailing List Vendor Advisory |
| http://secunia.com/advisories/41212 | Third Party Advisory |
| http://www.corelan.be:8800/index.php/2010/08/25/dll-hijacking-kb-2269637-the-unofficial-list/ | Broken Link |
| http://www.securityfocus.com/bid/42811 | Third Party Advisory VDB Entry |
| http://www.us-cert.gov/cas/techalerts/TA11-102A.html | Third Party Advisory US Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-025 | Patch Vendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12457 | Third Party Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2010-3190 | Patch Vendor Advisory |
| https://support.apple.com/HT205221 | Vendor Advisory |