CVE-2010-3133
Status: ModifiedHigh (9.3)—💥 Exploit
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Base score: 9.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 8.62%
- Percentile among all scored CVEs: 95
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Wireshark 1.2.10 - 'airpcap.dll' DLL Hijacking (8/24/2010)
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://secunia.com/advisories/41064
- http://www.exploit-db.com/exploits/14721/
- http://www.vupen.com/english/advisories/2010/2165
- http://www.vupen.com/english/advisories/2010/2243
- http://www.wireshark.org/security/wnpa-sec-2010-09.html
- http://www.wireshark.org/security/wnpa-sec-2010-10.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11498
- http://secunia.com/advisories/41064
- http://www.exploit-db.com/exploits/14721/
- http://www.vupen.com/english/advisories/2010/2165
- http://www.vupen.com/english/advisories/2010/2243
- http://www.wireshark.org/security/wnpa-sec-2010-09.html
- http://www.wireshark.org/security/wnpa-sec-2010-10.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11498
Raw JSON (NVD)
Show
{
"id": "CVE-2010-3133",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-08-26T18:36:36.013",
"references": [
{
"url": "http://secunia.com/advisories/41064",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/14721/",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2165",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2243",
"source": "cve@mitre.org"
},
{
"url": "http://www.wireshark.org/security/wnpa-sec-2010-09.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.wireshark.org/security/wnpa-sec-2010-10.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11498",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/41064",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/14721/",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2165",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2243",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.wireshark.org/security/wnpa-sec-2010-09.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.wireshark.org/security/wnpa-sec-2010-10.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11498",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark."
},
{
"lang": "es",
"value": "Una vulnerabilidad de ruta de búsqueda no confiable en Wireshark versiones 0.8.4 hasta 1.0.15 y versiones 1.2.0 hasta 1.2.10 permite a los usuarios locales, y posiblemente a atacantes remotos, ejecutar código arbitrario y conducir ataques de secuestro de DLL por medio de un archivo airpcap.dll de tipo caballo de Troya, y posiblemente otros DLL, que se encuentra en la misma carpeta que un archivo que inicia automáticamente Wireshark."
}
],
"lastModified": "2026-06-16T23:22:11.457",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAFB8C3D-A2D4-4C38-9ACE-F4DB672F1756",
"versionEndIncluding": "1.2.10"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:0.99.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31C43A78-E578-4B1C-8E33-24529E973E30"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:0.99.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A0D56DA6-3EB2-4074-8C43-A5FD93B1555B"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:0.99.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1074B30-F2E6-47CD-8491-29163811E07F"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:0.99.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10FAAC5E-DD4E-49EF-A051-2F80BACC20D1"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:0.99.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB52B779-7A2D-43E0-9F12-C65053002EBC"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:0.99.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2F7D104-7498-4C5F-AE75-6F04D5DA35B1"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:0.99.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "801B1795-3DC4-4BE3-A693-37B6BD116B14"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "978C483C-A6F7-456F-9488-833D520D4A1E"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BB94CE6-03D3-43C3-B765-AC36961CD83C"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37FADA30-FD98-42F3-80F1-E8794C77AC76"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8541E3F7-6DCF-4070-ACB0-C6B9C7BE32D2"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90E01A6A-D948-4701-9C4E-F8C3FCC52F2C"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCDCD888-3F3D-4ABC-B6D8-4A9E2C40265C"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA3F8A55-10DE-4197-9F9D-5F6570A94860"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0F1728E-ED97-4203-90D1-9E81E96BD7AF"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5629542-FD8E-4C7B-B396-BC76FB462083"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC077D96-1BBB-4F69-8C3A-F36CE3F3C668"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81DEE4BC-75DA-4F5C-9F57-1BF9BCE8290F"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F93E482E-258D-4C48-8886-350FE6FE4519"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.0.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86B3F8F4-80DA-4309-BF01-EB80D122794D"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B9A59A8-7319-4F1F-AA1D-801B5F7C1974"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0059BA2-86B2-4DA5-A6C1-7248D07BB37C"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C13C7D5-D344-45D2-9FF0-2C3388C94584"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D79DA61-F97C-4DCB-A2B7-FE67C5F10964"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84D6DFA0-53A2-424C-A31C-88FD683E5674"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B441815-DF95-462C-B9F9-43E2F0B04A45"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D09E4C0-0C75-4227-87E0-F2A06E240003"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DE4A9E3-5542-4483-9FA3-7F39C644563B"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD8A1D30-CB46-4B3D-BED5-1D045F3E1058"
},
{
"criteria": "cpe:2.3:a:wireshark:wireshark:1.2.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "977DA99C-54EC-4DEA-AD8B-E71C5F77022F"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/426.html\r\n\r\nCWE-426 - 'Untrusted Search Path Vulnerability'",
"sourceIdentifier": "cve@mitre.org"
}