PT-2012-1409 · Isao Maruoka · Pixia

Publicado

2012-09-06

·

Atualizado

2012-09-11

·

CVE-2010-5197

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pixia version 4.70j
Description The issue allows local users to gain privileges through an untrusted search path vulnerability. This can be exploited by placing a Trojan horse wintab32.dll file in the current working directory, particularly in a directory containing a .pxa file.
Recommendations For Pixia version 4.70j, consider restricting access to the wintab32.dll file or avoiding the use of untrusted directories to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-5197

Produtos afetados

Pixia