CVE-2010-3136

critical
Published 2010-08-26 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32.dll that is located in the same folder as a .skype file.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-14766 local windows verified
Glafkos Charalambous ยท 2010-08-25

Skype 4.2.0.169 - 'wab32.dll' DLL Hijacking

Source code queued for fetch โ€” refresh in a moment.

Application impact

VendorProductVersionsFixed
skypeskype3.1.0.150
skypeskype{"endIncluding":"4.2.0.169"}
skypeskype0.90.0.5
skypeskype0.90.0.10
skypeskype0.91.0.2
skypeskype0.92.0.4
skypeskype0.93.0.18
skypeskype0.93.1.1
skypeskype0.94.0.19
skypeskype0.94.0.28
skypeskype0.95.0.11
skypeskype0.95.0.25
skypeskype0.95.0.36
skypeskype0.95.0.40
skypeskype0.96.0.1
skypeskype0.96.0.3
skypeskype0.97.0.1
skypeskype0.97.0.3
skypeskype0.97.0.6
skypeskype0.97.0.40
skypeskype0.98.0.04
skypeskype0.98.0.6
skypeskype0.98.0.28
skypeskype0.98.0.42
skypeskype0.98.0.68
skypeskype1.0.0.9
skypeskype1.0.0.10
skypeskype1.0.0.18
skypeskype1.0.0.29
skypeskype1.0.0.94
skypeskype1.0.0.97
skypeskype1.0.0.100
skypeskype1.0.0.106
skypeskype1.1.0.6
skypeskype1.1.0.73
skypeskype1.1.0.79
skypeskype1.2.0.37
skypeskype1.2.0.41
skypeskype1.2.0.48
skypeskype1.3.0.45
skypeskype1.3.0.48
skypeskype1.3.0.51
skypeskype1.3.0.54
skypeskype1.3.0.55
skypeskype1.3.0.57
skypeskype1.3.0.60
skypeskype1.3.0.66
skypeskype1.4.0.71
skypeskype1.4.0.78
skypeskype1.4.0.84
skypeskype2.0.0.69
skypeskype2.0.0.73
skypeskype2.0.0.79
skypeskype2.0.0.81
skypeskype2.0.0.90
skypeskype2.0.0.97
skypeskype2.0.0.103
skypeskype2.0.0.105
skypeskype2.0.0.107
skypeskype2.5.0.72
skypeskype2.5.0.82
skypeskype2.5.0.91
skypeskype2.5.0.113
skypeskype2.5.0.122
skypeskype2.5.0.126
skypeskype2.5.0.130
skypeskype2.5.0.137
skypeskype2.5.0.141
skypeskype2.5.0.151
skypeskype2.5.0.154
skypeskype2.6.0.67
skypeskype2.6.0.74
skypeskype2.6.0.81
skypeskype2.6.0.97
skypeskype2.6.0.103
skypeskype2.6.0.105
skypeskype3.0.0.106
skypeskype3.0.0.123
skypeskype3.0.0.137
skypeskype3.0.0.154
skypeskype3.0.0.190
skypeskype3.0.0.198
skypeskype3.0.0.205
skypeskype3.0.0.209
skypeskype3.0.0.214
skypeskype3.0.0.216
skypeskype3.0.0.217
skypeskype3.0.0.218
skypeskype3.1.0.112
skypeskype3.1.0.134
skypeskype3.1.0.144
skypeskype3.1.0.147
skypeskype3.1.0.152
skypeskype3.2.0.53
skypeskype3.2.0.63
skypeskype3.2.0.82
skypeskype3.2.0.115
skypeskype3.2.0.145
skypeskype3.2.0.148
skypeskype3.2.0.152
skypeskype3.2.0.158
skypeskype3.2.0.163
skypeskype3.2.0.175
skypeskype3.5.0.107
skypeskype3.5.0.158
skypeskype3.5.0.178
skypeskype3.5.0.202
skypeskype3.5.0.214
skypeskype3.5.0.229
skypeskype3.5.0.234
skypeskype3.5.0.239
skypeskype3.6.0.127
skypeskype3.6.0.159
skypeskype3.6.0.216
skypeskype3.6.0.244
skypeskype3.6.0.248
skypeskype3.8.0.96
skypeskype3.8.0.115
skypeskype3.8.0.139
skypeskype3.8.0.144
skypeskype3.8.0.154
skypeskype3.8.0.180
skypeskype3.8.0.188
skypeskype4.0
skypeskype4.0.0.145
skypeskype4.0.0.150
skypeskype4.0.0.155
skypeskype4.0.0.161
skypeskype4.0.0.166
skypeskype4.0.0.168
skypeskype4.0.0.169
skypeskype4.0.0.176
skypeskype4.0.0.181
skypeskype4.0.0.206
skypeskype4.0.0.215
skypeskype4.0.0.216
skypeskype4.0.0.224
skypeskype4.0.0.226
skypeskype4.0.0.227
skypeskype4.1.0.130
skypeskype4.1.0.136
skypeskype4.1.0.141
skypeskype4.1.0.166
skypeskype4.1.0.179
skypeskype4.2.0.141
skypeskype4.2.0.152
skypeskype4.2.0.155
skypeskype4.2.0.158
skypeskype4.2.0.163
skypeskype4.2.0.166

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.