CVE-2010-3145 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 10.9% (pctl 96)
Patch early
A public exploit exists.
Description
Untrusted search path vulnerability in the BitLocker Drive Encryption API, as used in sdclt.exe in Backup Manager in Microsoft Windows Vista SP1 and SP2, allows local users to gain privileges via a Trojan horse fveapi.dll file in the current working directory, as demonstrated by a directory that contains a Windows Backup Catalog (.wbcat) file, aka "Backup Manager Insecure Library Loading Vulnerability."
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 10.94% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-08-27 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | windows vista |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Vista - 'fveapi.dll' BitLocker Drive Encryption API Hijacking | 2010-08-25 |
References
- http://www.exploit-db.com/exploits/14751/
- http://www.securitytracker.com/id?1024948
- http://www.us-cert.gov/cas/techalerts/TA11-011A.html
- http://www.vupen.com/english/advisories/2011/0074
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-001
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12273
- http://www.exploit-db.com/exploits/14751/
- http://www.securitytracker.com/id?1024948
- http://www.us-cert.gov/cas/techalerts/TA11-011A.html
- http://www.vupen.com/english/advisories/2011/0074
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-001
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12273
→ the Explorer · watch your stack · NVD