Vulnerabilities > CVE-2010-5240 - Unspecified vulnerability in Corel Coreldraw X5 and Photo-Paint X3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN corel
exploit available
Summary
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) CrlRib.dll file in the current working directory, as demonstrated by a directory that contains a .cdr, .cpt, .cmx, or .csl file. NOTE: some of these details are obtained from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description CorelDRAW X3 v13.0.0.576 DLL Hijacking Exploit (crlrib.dll). CVE-2010-5240,CVE-2014-8393. Local exploit for windows platform id EDB-ID:14786 last seen 2016-02-01 modified 2010-08-25 published 2010-08-25 reporter LiquidWorm source https://www.exploit-db.com/download/14786/ title CorelDRAW X3 13.0.0.576 - DLL Hijacking Exploit crlrib.dll description Corel PHOTO-PAINT X3 v13.0.0.576 DLL Hijacking Exploit (crlrib.dll). CVE-2010-5240,CVE-2014-8393. Local exploit for windows platform id EDB-ID:14787 last seen 2016-02-01 modified 2010-08-25 published 2010-08-25 reporter LiquidWorm source https://www.exploit-db.com/download/14787/ title Corel PHOTO-PAINT X3 13.0.0.576 - DLL Hijacking Exploit crlrib.dll
References
- http://secunia.com/advisories/41148
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4953.php
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4954.php
- http://secunia.com/advisories/41148
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4954.php
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4953.php