PT-2015-3489 · Threedify · Threedify Designer
Published
2015-01-01
·
Updated
2015-01-03
·
CVE-2011-5293
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ThreeDify Designer version 5.0.2
Description
The issue concerns the
cmdSave method in the ThreeDify.ThreeDifyDesigner.1 ActiveX control, which is part of the ActiveSolid.dll in ThreeDify Designer. This method allows remote attackers to write to arbitrary files by specifying a pathname in the argument.Recommendations
For ThreeDify Designer version 5.0.2, consider restricting access to the
cmdSave method until a patch is available. As a temporary workaround, avoid using the cmdSave method with untrusted input to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Threedify Designer