(MS11-025) Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)
Severity: HIGH
CVE Identifier: CVE-2010-3190
Advisory Date: JUN 17, 2011
DESCRIPTION
This security update addresses a vulnerability in certain applications built using the Microsoft Foundation Class (MFC) Library. This could allow remote code execution if a user opens a legitimate file related to the affected application/s and the file is located in the same network folder as a specially crafted library file.
TREND MICRO PROTECTION INFORMATION
For information on patches specific to the affected software, please proceed to the Microsoft Web page.
AFFECTED SOFTWARE AND VERSION
- Microsoft Visual Studio .NET 2003 Service Pack 1
- Microsoft Visual Studio 2005 Service Pack 1
- Microsoft Visual Studio 2008 Service Pack 1
- Microsoft Visual Studio 2010
- Microsoft Visual C++ 2005 Service Pack 1 Redistributable Package
- Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package
- Microsoft Visual C++ 2010 Redistributable Package