vendor:
Device Central CS5
by:
Glafkos Charalambous
7,8
CVSS
HIGH
DLL Hijacking
427
CWE
Product Name: Device Central CS5
Affected Version From: Adobe Device Central CS5 v3.0.0(376)
Affected Version To: Adobe Device Central CS5 v3.0.0(376)
Patch Exists: YES
Related CWE: N/A
CPE: a:adobe:device_central_cs5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x64 Ultimate
2010
Adobe Device Central CS5 DLL Hijacking Exploit (qtcf.dll)
This exploit is for Adobe Device Central CS5 v3.0.0(376) which is vulnerable to DLL hijacking. The vulnerable extensions are .adcp. The exploit is written in C and contains a list of functions that can be used to hijack the qtcf.dll library. The exploit was tested on Windows 7 x64 Ultimate.
Mitigation:
Adobe has released a patch to address this vulnerability.