First published: Tue Aug 31 2010(Updated: )
Untrusted search path vulnerability in Adobe Captivate 5.0.0.596, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .cptx file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Captivate | =5.0.0.596 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3191 is considered a critical vulnerability due to its potential to allow execution of arbitrary code.
CVE-2010-3191 affects Adobe Captivate by allowing local users and possibly remote attackers to exploit DLL hijacking through untrusted search paths.
The vulnerability CVE-2010-3191 specifically affects Adobe Captivate version 5.0.0.596 and possibly other versions.
To mitigate CVE-2010-3191, ensure that you do not use untrusted .cptx files and regularly update Adobe Captivate to the latest security patch.
CVE-2010-3191 can enable DLL hijacking attacks through the placement of malicious dwmapi.dll files in the same directory as .cptx files.