MS11-025: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)

This script is Copyright (C) 2011-2014 Tenable Network Security, Inc.


Synopsis :

Arbitrary code can be executed on the remote host through the
Microsoft Foundation Class library.

Description :

The remote Windows host contains a version of the Microsoft Foundation
Class (MFC) library affected by an insecure library loading
vulnerability. The path used for loading external libraries is not
securely restricted.

An attacker can exploit this by tricking a user into opening an MFC
application in a directory that contains a malicious DLL, resulting in
arbitrary code execution.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms11-025

Solution :

Microsoft has released a set of patches for Visual Studio .NET 2003,
2005, and 2008, as well as Visual C++ 2005, 2008, and 2010.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 53382 ()

Bugtraq ID: 42811

CVE ID: CVE-2010-3190