PT-2012-1409 · Isao Maruoka · Pixia
Publicado
2012-09-06
·
Atualizado
2012-09-11
·
CVE-2010-5197
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Pixia version 4.70j
Description
The issue allows local users to gain privileges through an untrusted search path vulnerability. This can be exploited by placing a Trojan horse wintab32.dll file in the current working directory, particularly in a directory containing a .pxa file.
Recommendations
For Pixia version 4.70j, consider restricting access to the wintab32.dll file or avoiding the use of untrusted directories to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pixia