PT-2012-1409 · Isao Maruoka · Pixia

Published

2012-09-06

·

Updated

2012-09-11

·

CVE-2010-5197

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pixia version 4.70j
Description The issue allows local users to gain privileges through an untrusted search path vulnerability. This can be exploited by placing a Trojan horse wintab32.dll file in the current working directory, particularly in a directory containing a .pxa file.
Recommendations For Pixia version 4.70j, consider restricting access to the wintab32.dll file or avoiding the use of untrusted directories to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-5197

Affected Products

Pixia