RULE(RULE ID:1905248)

Rule General Information
Release Date: 2013-06-27
Rule Name: Microsoft Windows Branchcache DLL Loading Arbitrary Code Execution Vulnerability -2 (CVE-2010-3966)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "BranchCache Insecure Library Loading Vulnerability."
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: http://www.microsoft.com/technet/security/Bulletin/MS10-095.mspx
SecurityFocusBID:45295
SecurityTrackerID:1024877
Solutions
Microsoft has released a patch MS10-095 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/Bulletin/MS10-095.mspx