CVE Reference: CVE-2010-3152

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2010-3152

Description:
Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.

CVE Status:
Candidate

References:

ST
  1024865

SAID
  Secunia Advisory: SA41134

OSVDB
  67534

EXPLOIT-DB
  http://www.exploit-db.com/exploits/14773/

CONFIRM
  http://www.adobe.com/support/security/bulletins/apsb10-29.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/513335/100/0/threaded


Return to the previous page.