PT-2015-3489 · Threedify · Threedify Designer

Publicado

2015-01-01

·

Atualizado

2015-01-03

·

CVE-2011-5293

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ThreeDify Designer version 5.0.2
Description The issue concerns the cmdSave method in the ThreeDify.ThreeDifyDesigner.1 ActiveX control, which is part of the ActiveSolid.dll in ThreeDify Designer. This method allows remote attackers to write to arbitrary files by specifying a pathname in the argument.
Recommendations For ThreeDify Designer version 5.0.2, consider restricting access to the cmdSave method until a patch is available. As a temporary workaround, avoid using the cmdSave method with untrusted input to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-5293

Produtos afetados

Threedify Designer