PT-2010-4594 · Adobe · Device Central Cs5
Glafkos Charalambous
·
Published
2010-08-27
·
Updated
2018-10-10
·
CVE-2010-3149
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Device Central CS5 version 3.0.0(376)
Adobe Device Central CS5 version 3.0.1.0 (3027)
Adobe Device Central CS5 (other versions possibly affected)
Description
The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks. This is achieved via a Trojan horse
qtcf.dll located in the same folder as an ADCP file.Recommendations
For Adobe Device Central CS5 version 3.0.0(376), consider removing or restricting access to the
qtcf.dll file until a patch is available.
For Adobe Device Central CS5 version 3.0.1.0 (3027), avoid using the software with untrusted ADCP files until the issue is resolved.
For other possibly affected versions of Adobe Device Central CS5, restrict access to the qtcf.dll file and avoid using the software with untrusted ADCP files until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Device Central Cs5