First published: Thu Jan 15 2015(Updated: )
Untrusted search path vulnerability in Corel PDF Fusion allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll file that is located in the same folder as the file being processed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Corel PDF Fusion |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-8396 is classified as medium due to its potential for local users to execute arbitrary code.
To fix CVE-2014-8396, ensure that you do not allow untrusted DLLs in folders where Corel PDF Fusion processes files, and update to the latest version of the software if available.
Users of Corel PDF Fusion are affected by CVE-2014-8396, specifically those who may interact with files containing untrusted DLLs.
CVE-2014-8396 allows local users to conduct DLL hijacking attacks, which can lead to arbitrary code execution.
A possible workaround for CVE-2014-8396 is to restrict file access permissions and avoid processing files from untrusted sources.