peter bassill · operator
$ cve CVE-2011-0403 JSON

CVE-2011-0403 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a CUE file.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS7.07% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2011-01-11
Last modified2026-06-16

Affected (1)

VendorProduct
imgburnimgburn

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD