CVE-2013-0733: Critical severity Corel PaintShop Pro vulnerability
Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jpg file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0733?
CVE-2013-0733 has a high severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2013-0733?
To fix CVE-2013-0733, users should update to the latest version of Corel PaintShop Pro that resolves this vulnerability.
What types of attacks are possible with CVE-2013-0733?
CVE-2013-0733 allows for DLL hijacking attacks, enabling an attacker to execute arbitrary code.
Which versions of Corel PaintShop Pro are affected by CVE-2013-0733?
CVE-2013-0733 affects Corel PaintShop Pro X5 up to version 15.2.0.2 and X6 up to version 16.0.0.113.
Can CVE-2013-0733 be exploited by local users?
Yes, CVE-2013-0733 can be exploited by local users executing malicious files in the same folder as image files.