Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-3149. PoCs published by Glafkos Charalambous.
AI-analyzed exploit summary This exploit leverages DLL hijacking in Adobe Device Central CS5 by providing a malicious qtcf.dll. The DLL exports multiple functions that trigger a pwn() function, likely executing arbitrary code when loaded by the vulnerable application.
Description
Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse qtcf.dll that is located in the same folder as an ADCP file.
Exploits (1)
This exploit leverages DLL hijacking in Adobe Device Central CS5 by providing a malicious qtcf.dll. The DLL exports multiple functions that trigger a pwn() function, likely executing arbitrary code when loaded by the vulnerable application.