PT-2012-1409 · Isao Maruoka · Pixia
Published
2012-09-06
·
Updated
2012-09-11
·
CVE-2010-5197
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Pixia version 4.70j
Description
The issue allows local users to gain privileges through an untrusted search path vulnerability. This can be exploited by placing a Trojan horse wintab32.dll file in the current working directory, particularly in a directory containing a .pxa file.
Recommendations
For Pixia version 4.70j, consider restricting access to the wintab32.dll file or avoiding the use of untrusted directories to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pixia