Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-3155. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit leverages DLL hijacking in Adobe ExtendedScript Toolkit CS5 by placing a malicious 'dwmapi.dll' in the same directory as a '.jsx' file. When the application loads, it executes arbitrary code via the hijacked DLL.
Description
Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jsx file.
Exploits (1)
This exploit leverages DLL hijacking in Adobe ExtendedScript Toolkit CS5 by placing a malicious 'dwmapi.dll' in the same directory as a '.jsx' file. When the application loads, it executes arbitrary code via the hijacked DLL.