Back

CVE-2005-2938

Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.

Published: Nov 18, 2005 Modified: Jun 16, 2026
CWE-264

CVSS Metrics

Affected Products (2)

Vendor Product Version
apple itunes 4.7.1.30
apple itunes 5.0

GitHub Security Advisory GHSA-36xg-989x-49mx

Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.39%

Top 68% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS GitHub