CVE Vulnerabilities

CVE-2016-2521

Published: Feb 28, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 on Windows allows local users to gain privileges via a Trojan horse riched20.dll.dll file in the current working directory, related to use of QLibrary.

Affected Software

NameVendorStart VersionEnd Version
WiresharkWireshark1.12.0 (including)1.12.0 (including)
WiresharkWireshark1.12.1 (including)1.12.1 (including)
WiresharkWireshark1.12.2 (including)1.12.2 (including)
WiresharkWireshark1.12.3 (including)1.12.3 (including)
WiresharkWireshark1.12.4 (including)1.12.4 (including)
WiresharkWireshark1.12.5 (including)1.12.5 (including)
WiresharkWireshark1.12.6 (including)1.12.6 (including)
WiresharkWireshark1.12.7 (including)1.12.7 (including)
WiresharkWireshark1.12.8 (including)1.12.8 (including)
WiresharkWireshark1.12.9 (including)1.12.9 (including)
WiresharkWireshark2.0.0 (including)2.0.0 (including)
WiresharkWireshark2.0.1 (including)2.0.1 (including)
WiresharkUbuntuartful*
WiresharkUbuntubionic*
WiresharkUbuntuesm-apps/bionic*
WiresharkUbuntuesm-apps/xenial*
WiresharkUbuntuesm-infra-legacy/trusty*
WiresharkUbuntuprecise*
WiresharkUbuntutrusty*
WiresharkUbuntutrusty/esm*
WiresharkUbuntuwily*
WiresharkUbuntuxenial*
WiresharkUbuntuyakkety*
WiresharkUbuntuzesty*

References