vendor:
Cool iPhone Ringtone Maker
by:
anT!-Tr0J4n
7.5
CVSS
HIGH
Arbitrary Code Execution
119
CWE
Product Name: Cool iPhone Ringtone Maker
Affected Version From: 2.2.2003
Affected Version To: 2.2.2003
Patch Exists: NO
Related CWE:
CPE: cool_iphone_ringtone_maker:2.2.3
Platforms Tested:
2010
Cool iPhone Ringtone Maker DLL Hijacking Vulnerability
An attacker can exploit this vulnerability by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Mitigation:
Apply the latest version of Cool iPhone Ringtone Maker that has addressed this vulnerability.