PT-2010-4594 · Adobe · Device Central Cs5
Glafkos Charalambous
·
Publicado
2010-08-27
·
Atualizado
2018-10-10
·
CVE-2010-3149
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Device Central CS5 version 3.0.0(376)
Adobe Device Central CS5 version 3.0.1.0 (3027)
Adobe Device Central CS5 (other versions possibly affected)
Description
The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks. This is achieved via a Trojan horse
qtcf.dll located in the same folder as an ADCP file.Recommendations
For Adobe Device Central CS5 version 3.0.0(376), consider removing or restricting access to the
qtcf.dll file until a patch is available.
For Adobe Device Central CS5 version 3.0.1.0 (3027), avoid using the software with untrusted ADCP files until the issue is resolved.
For other possibly affected versions of Adobe Device Central CS5, restrict access to the qtcf.dll file and avoid using the software with untrusted ADCP files until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Device Central Cs5