CVE-2010-3152

Adobe Illustrator CS4-CS5 - RCE

Title source: llm

Description

Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.

Exploits (1)

exploitdb WORKING POC
by Glafkos Charalambous · clocalwindows
https://www.exploit-db.com/exploits/14773

Scores

EPSS 0.0463
EPSS Percentile 89.3%

Details

Status published
Products (2)
adobe/illustrator 14.0
adobe/illustrator 15.0.1
Published Aug 27, 2010
Tracked Since Feb 18, 2026