PT-2010-4597 · Adobe · Illustrator

Glafkos Charalambous

·

Published

2010-08-27

·

Updated

2018-10-10

·

CVE-2010-3152

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Illustrator versions 14.0.0 through 15.0.1 and earlier
Description The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks. This can be achieved via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.
Recommendations For Adobe Illustrator versions 14.0.0 through 15.0.1 and earlier, update to a version later than 15.0.1 to resolve the issue. At the moment, there is no information about other versions that may be affected and how to fix them.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-3152

Affected Products

Illustrator