Untrusted search path vulnerability in Bandisoft Bandizip before 3.10 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory.
2014-02-14T13:10:30.950
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.9 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | bandisoft | bandizip | ≤ 3.09 | Yes |
| Application | bandisoft | bandizip | 3.00 | Yes |
| Application | bandisoft | bandizip | 3.01 | Yes |
| Application | bandisoft | bandizip | 3.02 | Yes |
| Application | bandisoft | bandizip | 3.03 | Yes |
| Application | bandisoft | bandizip | 3.04 | Yes |
| Application | bandisoft | bandizip | 3.05 | Yes |
| Application | bandisoft | bandizip | 3.06 | Yes |
| Application | bandisoft | bandizip | 3.07 | Yes |
| Application | bandisoft | bandizip | 3.08 | Yes |