Lucene search

K
kasperskyKaspersky LabKLA10037
HistoryOct 18, 2010 - 12:00 a.m.

KLA10037 ACE vulnerability in Adobe InDesign

2010-10-1800:00:00
Kaspersky Lab
threats.kaspersky.com
19

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.02

Percentile

89.0%

A critical vulnerability was found in Adobe InDesign and InCopy. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited locally and possibly remotely at a point related to an untrusted path via DLL hijacking.

Original advisories

Adobe bulletin

Exploitation

Public exploits exist for this vulnerability.

Related products

Adobe-InDesign-CS5

CVE list

CVE-2010-3153 critical

Solution

Update to latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Adobe InDesign versions CS5 7.0.2 and earlier for WindowsAdobe InDesign Server versions CS5  7.0.2 and earlier for WindowsAdobe InCopy versions CS5 7.0.2 and earlier for Windows

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.02

Percentile

89.0%