« Volver al listado

CVE-2010-2600

Estado: ModificadaAlta (9.3)—

Untrusted search path vulnerability in BlackBerry Desktop Software before 6.0.0.47 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Blackberry.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-2600",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-09-15T18:00:42.527",
  "references": [
    {
      "url": "http://secunia.com/advisories/41346",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/41398",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.blackberry.com/btsc/KB24242",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/43139",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1024425",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6843",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/41346",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/41398",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.blackberry.com/btsc/KB24242",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/43139",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1024425",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6843",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Untrusted search path vulnerability in BlackBerry Desktop Software before 6.0.0.47 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Blackberry."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad ruta de búsqueda no confiable en BlackBerry Desktop Software anterior a v6.0.0.47 permite a los usuarios locales, y posiblemente a los atacantes remotos, ejecutar código a su elección y y producir un ataque de secuestro de DLL, a través de un troyano DLL que está ubicado en la misma carpeta que un fichero que sea procesado por Blackberry."
    }
  ],
  "lastModified": "2026-06-16T23:21:03.620",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rim:blackberry_desktop_software:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83FAB36B-C391-48CD-9288-B863B4AEEDF3",
              "versionEndIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:rim:blackberry_desktop_software:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5D351E1-40DE-4B6B-B4F1-E8DC8CAE2394"
            },
            {
              "criteria": "cpe:2.3:a:rim:blackberry_desktop_software:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F6E498C-19BA-4446-B294-48C43B683503"
            },
            {
              "criteria": "cpe:2.3:a:rim:blackberry_desktop_software:4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2678689F-7A01-4A7A-9FF7-EE1D88745190"
            },
            {
              "criteria": "cpe:2.3:a:rim:blackberry_desktop_software:4.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41DF363C-8CD9-405A-A91F-76960CA343C9"
            },
            {
              "criteria": "cpe:2.3:a:rim:blackberry_desktop_software:4.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F948832-AAF4-43E8-A070-E7C225E869A9"
            },
            {
              "criteria": "cpe:2.3:a:rim:blackberry_desktop_software:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E268C82-6292-4969-9179-5B007BFDD6BC"
            },
            {
              "criteria": "cpe:2.3:a:rim:blackberry_desktop_software:5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1469FEE3-BE68-4028-8BD1-C60B7831955E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/426.html\r\n\r\n'CWE-426: Untrusted Search Path'",
  "sourceIdentifier": "cve@mitre.org"
}