PT-2010-4597 · Adobe · Illustrator
Glafkos Charalambous
·
Published
2010-08-27
·
Updated
2018-10-10
·
CVE-2010-3152
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Illustrator versions 14.0.0 through 15.0.1 and earlier
Description
The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks. This can be achieved via a Trojan horse
dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.Recommendations
For Adobe Illustrator versions 14.0.0 through 15.0.1 and earlier, update to a version later than 15.0.1 to resolve the issue.
At the moment, there is no information about other versions that may be affected and how to fix them.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Illustrator