« Volver al listado

CVE-2010-3158

Estado: ModificadaMedia (6.9)—

Una vulnerabilidad de ruta de búsqueda en Lhaplus antes de la v1.58 permite a usuarios locales conseguir privilegios a través de un archivo caballo de Troya ejecutable en el directorio de trabajo actual.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-3158",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-10-19T20:00:04.190",
  "references": [
    {
      "url": "http://jvn.jp/jp/JVN18774708/index.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000039.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://secunia.com/advisories/41742",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www7a.biglobe.ne.jp/~schezo/dll_vul.html",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/64436",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/jp/JVN18774708/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000039.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/41742",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www7a.biglobe.ne.jp/~schezo/dll_vul.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/64436",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Untrusted search path vulnerability in Lhaplus before 1.58 allows local users to gain privileges via a Trojan horse executable file in the current working directory."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de ruta de búsqueda en Lhaplus antes de la v1.58 permite a usuarios locales conseguir privilegios a través de un archivo caballo de Troya ejecutable en el directorio de trabajo actual."
    }
  ],
  "lastModified": "2026-06-16T23:22:15.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:lhaplus:lhaplus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC299EC5-4D89-4616-AA3B-304BE1672611",
              "versionEndIncluding": "1.57"
            },
            {
              "criteria": "cpe:2.3:a:lhaplus:lhaplus:1.52:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F1647D1-2FEF-46B9-9768-B975FFC26F6E"
            },
            {
              "criteria": "cpe:2.3:a:lhaplus:lhaplus:1.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14B4D2EB-7A82-4672-9819-7090923A16C1"
            },
            {
              "criteria": "cpe:2.3:a:lhaplus:lhaplus:1.55:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECC807E5-92D9-4BAA-9043-2C1E7F4540D6"
            },
            {
              "criteria": "cpe:2.3:a:lhaplus:lhaplus:1.56:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0657CD5D-2FC2-41EB-8B5C-6ABAC104F363"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/426.html\r\n\r\n'CWE-426: Untrusted Search Path'",
  "sourceIdentifier": "vultures@jpcert.or.jp"
}