9.3
CVSSv2

CVE-2010-3154

Published: 27/08/2010 Updated: 30/08/2010
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .mxi or .mxp file.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe extension manager cs5 5.0.298

Exploits

/* Adobe Extension Manager CS5 v50298 (dwmapidll) DLL Hijacking Exploit Vendor: Adobe Systems Inc Product Web Page: wwwadobecom Affected Version: CS5 v50298 Summary: Easily install new extensions and manage the ones you already have with the Adobe Extension Manager Desc: Adobe Extension Manager CS5 suffers from a dll hija ...