PT-2010-4577 · Adobe · Dreamweaver Cs5

Bruno Filipe

+1

·

Publicado

2010-08-26

·

Atualizado

2017-09-19

·

CVE-2010-3132

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Dreamweaver CS5 version 11.0 build 4916 Adobe Dreamweaver CS5 version 11.0 build 4909 Adobe Dreamweaver CS5 (other versions probably affected)
Description The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks. This can be achieved via a Trojan horse mfc90loc.dll or dwmapi.dll located in the same folder as a CSS, PHP, ASP, or other file that automatically launches the software.
Recommendations For Adobe Dreamweaver CS5 version 11.0 build 4916, consider removing or restricting access to the mfc90loc.dll and dwmapi.dll files in the same folder as files that launch the software. For Adobe Dreamweaver CS5 version 11.0 build 4909, consider removing or restricting access to the mfc90loc.dll and dwmapi.dll files in the same folder as files that launch the software. For other probably affected versions of Adobe Dreamweaver CS5, consider removing or restricting access to the mfc90loc.dll and dwmapi.dll files in the same folder as files that launch the software.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-3132

Produtos afetados

Dreamweaver Cs5