9.3
CVSSv2

CVE-2010-3127

Published: 26/08/2010 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe photoshop 12.0

adobe photoshop 10.0

adobe photoshop 11.0

adobe photoshop 9.0

adobe photoshop 9.0.1

adobe photoshop 9.0.2

Exploits

/* Exploit Title: Adobe Photoshop CS2 DLL Hijacking Exploit (Wintab32dll) Date: August 25, 2010 Author: storm (storm@gonullyourselforg) Version: CS2 (90) - Other versions are very possibly exploitable too Tested on: Windows Vista SP2 wwwgonullyourselforg/ gcc -shared -o Wintab32dll Photoshop-DLLc As far as I can tell, every file e ...