9.3
CVSSv2

CVE-2010-3149

Published: 27/08/2010 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse qtcf.dll that is located in the same folder as an ADCP file.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe device central cs5 3.0.0\\(376\\)

Exploits

/* Exploit Title: Adobe Device Central CS5 DLL Hijacking Exploit (qtcfdll) Date: August 24, 2010 Author: Glafkos Charalambous (glafkos[@]astalavista[dot]com) Version: Latest CS5 v300(376) Tested on: Windows 7 x64 Ultimate Vulnerable extensions: adcp Greetz: Astalavista, OffSEC, Exploit-DB */ #include <windowsh> #define DllExport __dec ...