6.9
CVSSv2

CVE-2010-5236

Published: 07/09/2012 Updated: 07/09/2012
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a Trojan horse homeutils9.dll file in the current working directory, as demonstrated by a directory that contains a .roxio, .c2d, or .gi file. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

roxio easy media creator 9.0.136

Exploits

/* Exploit Title: Roxio Creator DE DLL Hijacking Exploit (HomeUtils9dll) Date: August 25, 2010 Author: storm (storm@gonullyourselforg) Version: 90116 - Other versions are very possibly exploitable too Tested on: Windows Vista SP2 wwwgonullyourselforg/ gcc -shared -o HomeUtils9dll Roxio-DLLc c2d, gi, and roxio files are affect ...