Vulnerability CVE-2013-1361


Published: 2014-01-21

Description:
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth.

Type:

CWE-Other

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Lenovo -> Thinkpad bluetooth with enhanced data rate software 

 References:
http://xforce.iss.net/xforce/xfdb/81428
http://www.securityfocus.com/bid/57504
http://www.osvdb.org/89483
http://technet.microsoft.com/en-us/security/msvr/msvr13-001
http://secunia.com/advisories/51846

Copyright 2021, cxsecurity.com

 

Back to Top