PT-2010-4792 · Idm Computer Solutions · Ultraedit
Published
2010-09-16
·
Updated
2018-10-30
·
CVE-2010-3402
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IDM Computer Solutions UltraEdit versions 16.10.0.1036, 16.20.0.1009
Description
The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll. This can occur when the dwmapi.dll is located in the same folder as certain file types, including bin, cpp, css, c, dat, hpp, html, h, ini, java, log, mak, php, prj, txt, or xml files.
Recommendations
For versions 16.10.0.1036 and 16.20.0.1009, consider restricting access to the affected file types or removing them from the search path to minimize the risk of exploitation. As a temporary workaround, avoid using the vulnerable UltraEdit versions in environments where untrusted files may be present.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ultraedit