CVE-2010-3148 describes an untrusted search path vulnerability in Microsoft Visio 2003 SP3, allowing local privilege escalation. An attacker can exploit this by placing a malicious mfc71enu.dll file in the same directory as a Visio document (.vsd, .vdx, .vst, or .vtx). This vulnerability carries a critical CVSS score of 9.3, indicating high severity with complete compromise of confidentiality, integrity, and availability. While not actively exploited in the wild (no KEV entry), public exploit code exists on ExploitDB, and its EPSS score suggests a low likelihood of exploitation. There is no significant community discussion or media coverage surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:visio:2003:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.