PT-2010-5208 · Adobe · Flash Player

Simon Raner

·

Published

2010-10-19

·

Updated

2018-10-10

·

CVE-2010-3976

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Flash Player versions prior to 9.0.289.0 Adobe Flash Player versions 10.x prior to 10.1.102.64
Description The issue allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll. This occurs when the malicious dwmapi.dll is located in the same folder as a file that is processed by Flash Player.
Recommendations For Adobe Flash Player versions prior to 9.0.289.0, update to version 9.0.289.0 or later. For Adobe Flash Player versions 10.x prior to 10.1.102.64, update to version 10.1.102.64 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-3976

Affected Products

Flash Player