CVE-2010-0103
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
10/03/2010
Last modified:
11/04/2025
Description
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary programs onto a Windows PC, and execute these programs, via a request to TCP port 7777.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:energizer:duo_usb:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.kb.cert.org/vuls/id/154421
- http://www.marketwatch.com/story/energizer-announces-duo-charger-and-usb-charger-software-problem-2010-03-05
- http://www.securityfocus.com/bid/38571
- http://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software
- http://www.kb.cert.org/vuls/id/154421
- http://www.marketwatch.com/story/energizer-announces-duo-charger-and-usb-charger-software-problem-2010-03-05
- http://www.securityfocus.com/bid/38571
- http://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software



