First published: Fri Aug 27 2010(Updated: )
Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Illustrator 2024 | =14.0 | |
Adobe Illustrator 2024 | =15.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3152 has a high severity rating due to its potential for allowing arbitrary code execution.
To mitigate CVE-2010-3152, update Adobe Illustrator to the latest version that addresses this vulnerability.
CVE-2010-3152 affects users of Adobe Illustrator CS4 14.0.0, CS5 15.0.1, and possibly earlier versions.
CVE-2010-3152 can enable local users and potentially remote attackers to conduct DLL hijacking attacks.
CVE-2010-3152 was publicly disclosed in August 2010.