First published: Thu Sep 06 2012(Updated: )
Multiple untrusted search path vulnerabilities in IBM Lotus Symphony 1.3.0 20090908.0900 allow local users to gain privileges via a Trojan horse (1) eclipse_1114.dll or (2) emser645mi.dll file in the current working directory, as demonstrated by a directory that contains a .odm, .odt, .otp, .stc, .stw, .sxg, or .sxw file. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Symphony | =1.3.0.20090908.0900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-5204 is classified as a high-severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2010-5204, remove any incompatible DLL files from the current working directory or update to a secure version of IBM Lotus Symphony.
CVE-2010-5204 affects users of IBM Lotus Symphony version 1.3.0 20090908.0900.
CVE-2010-5204 allows attackers to exploit untrusted search path vulnerabilities to execute malicious DLL files.
There is no official patch for CVE-2010-5204, so it is recommended to avoid using the affected software version.