9.3
CVSSv2

CVE-2010-3151

Published: 27/08/2010 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe onlocation_cs4 4.0.1

adobe onlocation_cs4 4.0.2

adobe onlocation_cs4 4.0.3

Exploits

/* Exploit Title: Adobe On Location CS4 DLL Hijacking Exploit (ibfs32dll) Date: August 25, 2010 Author: Glafkos Charalambous (glafkos[@]astalavista[dot]com) Version: CS4 Build 315 Tested on: Windows 7 x64 Ultimate Vulnerable extensions: olproj Greetz: Astalavista, OffSEC, Exploit-DB */ #include <windowsh> BOOL WINAPI DllMain ( ...