PT-2015-3489 · Threedify · Threedify Designer

Published

2015-01-01

·

Updated

2015-01-03

·

CVE-2011-5293

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ThreeDify Designer version 5.0.2
Description The issue concerns the cmdSave method in the ThreeDify.ThreeDifyDesigner.1 ActiveX control, which is part of the ActiveSolid.dll in ThreeDify Designer. This method allows remote attackers to write to arbitrary files by specifying a pathname in the argument.
Recommendations For ThreeDify Designer version 5.0.2, consider restricting access to the cmdSave method until a patch is available. As a temporary workaround, avoid using the cmdSave method with untrusted input to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5293

Affected Products

Threedify Designer