CVE-2010-0103

high

Description

UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary programs onto a Windows PC, and execute these programs, via a request to TCP port 7777.

References

http://www.kb.cert.org/vuls/id/154421

http://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software

Details

Source: Mitre, NVD

Published: 2010-03-10

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High