PT-2010-4577 · Adobe · Dreamweaver Cs5

Bruno Filipe

+1

·

Published

2010-08-26

·

Updated

2017-09-19

·

CVE-2010-3132

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Dreamweaver CS5 version 11.0 build 4916 Adobe Dreamweaver CS5 version 11.0 build 4909 Adobe Dreamweaver CS5 (other versions probably affected)
Description The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks. This can be achieved via a Trojan horse mfc90loc.dll or dwmapi.dll located in the same folder as a CSS, PHP, ASP, or other file that automatically launches the software.
Recommendations For Adobe Dreamweaver CS5 version 11.0 build 4916, consider removing or restricting access to the mfc90loc.dll and dwmapi.dll files in the same folder as files that launch the software. For Adobe Dreamweaver CS5 version 11.0 build 4909, consider removing or restricting access to the mfc90loc.dll and dwmapi.dll files in the same folder as files that launch the software. For other probably affected versions of Adobe Dreamweaver CS5, consider removing or restricting access to the mfc90loc.dll and dwmapi.dll files in the same folder as files that launch the software.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-3132

Affected Products

Dreamweaver Cs5