CVE-2010-3152 Information

Description

Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0 CS5 15.0.1 and earlier and possibly other versions allows local users and possibly remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.

Reference

http://osvdb.org/67534 http://secunia.com/advisories/41134 http://www.adobe.com/support/security/bulletins/apsb10-29.html http://www.exploit-db.com/exploits/14773/ http://www.securityfocus.com/archive/1/513335/100/0/threaded http://www.securitytracker.com/id?1024865 http://www.vupen.com/english/advisories/2010/2198

Share on: