PT-2010-4597 · Adobe · Illustrator

Glafkos Charalambous

·

Publicado

2010-08-27

·

Atualizado

2018-10-10

·

CVE-2010-3152

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Illustrator versions 14.0.0 through 15.0.1 and earlier
Description The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks. This can be achieved via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.
Recommendations For Adobe Illustrator versions 14.0.0 through 15.0.1 and earlier, update to a version later than 15.0.1 to resolve the issue. At the moment, there is no information about other versions that may be affected and how to fix them.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-3152

Produtos afetados

Illustrator