Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 on Windows allows local users to gain privileges via a Trojan horse riched20.dll.dll file in the current working directory, related to use of QLibrary.
2016-02-28T04:59:00.120
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | wireshark | wireshark | 1.12.0 | Yes |
| Application | wireshark | wireshark | 1.12.1 | Yes |
| Application | wireshark | wireshark | 1.12.2 | Yes |
| Application | wireshark | wireshark | 1.12.3 | Yes |
| Application | wireshark | wireshark | 1.12.4 | Yes |
| Application | wireshark | wireshark | 1.12.5 | Yes |
| Application | wireshark | wireshark | 1.12.6 | Yes |
| Application | wireshark | wireshark | 1.12.7 | Yes |
| Application | wireshark | wireshark | 1.12.8 | Yes |
| Application | wireshark | wireshark | 1.12.9 | Yes |
| Application | wireshark | wireshark | 2.0.0 | Yes |
| Application | wireshark | wireshark | 2.0.1 | Yes |