vendor:
ExtendScript Toolkit CS5
by:
Gjoko 'LiquidWorm' Krstic
7,2
CVSS
HIGH
DLL Hijacking
427
CWE
Product Name: ExtendScript Toolkit CS5
Affected Version From: CS5 v3.5.0.52
Affected Version To: CS5 v3.5.0.52
Patch Exists: NO
Related CWE: N/A
CPE: a:adobe:extendscript_toolkit_cs5:3.5.0.52
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2010
Adobe ExtendedScript Toolkit CS5 v3.5.0.52 (dwmapi.dll) DLL Hijacking Exploit
Adobe ExtendScript Toolkit CS5 suffers from a dll hijacking vulnerability that enables the attacker to execute arbitrary code on a local level. The vulnerable extension is .jsx thru dwmapi.dll library.
Mitigation:
Ensure that the application is running with the least privileges necessary and that all files are stored in a secure location.