(MS11-025) Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212)
Publish Date: 17 juin 2011
Gravité: : Élevé
Identifiant(s) CVE: : CVE-2010-3190
Date du conseil: 17 juin 2011
Description
This security update addresses a vulnerability in certain applications built using the Microsoft Foundation Class (MFC) Library. This could allow remote code execution if a user opens a legitimate file related to the affected application/s and the file is located in the same network folder as a specially crafted library file.
Information Exposure Rating:
For information on patches specific to the affected software, please proceed to the Microsoft Web page.
Affected software and version:
- Microsoft Visual Studio .NET 2003 Service Pack 1
- Microsoft Visual Studio 2005 Service Pack 1
- Microsoft Visual Studio 2008 Service Pack 1
- Microsoft Visual Studio 2010
- Microsoft Visual C++ 2005 Service Pack 1 Redistributable Package
- Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package
- Microsoft Visual C++ 2010 Redistributable Package