9.3
CVSSv2

CVE-2010-3155

Published: 27/08/2010 Updated: 09/09/2010
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jsx file.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe extendedscript toolkit cs5 3.5.0.52

Exploits

/* Adobe ExtendedScript Toolkit CS5 v35052 (dwmapidll) DLL Hijacking Exploit Vendor: Adobe Systems Inc Product Web Page: wwwadobecom Affected Version: CS5 v35052 ExtendScript 4123 ScriptUI 5137 Summary: The ExtendScript Toolkit (ESTK) 350 is a scripting utility included with Adobe® Creative Suite CS5 and other Adobe ...