peter bassill · operator
$ cve CVE-2010-3145 JSON

CVE-2010-3145 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 10.9% (pctl 96)

Patch early

A public exploit exists.

Description

Untrusted search path vulnerability in the BitLocker Drive Encryption API, as used in sdclt.exe in Backup Manager in Microsoft Windows Vista SP1 and SP2, allows local users to gain privileges via a Trojan horse fveapi.dll file in the current working directory, as demonstrated by a directory that contains a Windows Backup Catalog (.wbcat) file, aka "Backup Manager Insecure Library Loading Vulnerability."

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS10.94% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2010-08-27
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftwindows vista

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD