Record summary

CVE-2010-3155 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.

Description

Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jsx file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAdobe ExtendedScript Toolkit CS5 3.5.0.52 - 'dwmapi.dll' DLL HijackingExploitDB exploitby LiquidWormNot analyzed1 file
ExploitDB

PoC details

References

3