Ulead COOL 3D Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
BID:47067
Info
Ulead COOL 3D Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 47067 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2011 12:00AM |
| Updated: | Mar 28 2011 12:00AM |
| Credit: | Houssam Sahli |
| Vulnerable: |
Corel Ulead COOL 3D 3.5 |
| Not Vulnerable: | |
Discussion
Ulead COOL 3D Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
Ulead COOL 3D is prone to multiple vulnerabilities that let attackers execute arbitrary code.
An attacker can exploit these issues by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Ulead COOL 3D 3.5 is vulnerable; other versions may also be affected.
Ulead COOL 3D is prone to multiple vulnerabilities that let attackers execute arbitrary code.
An attacker can exploit these issues by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Ulead COOL 3D 3.5 is vulnerable; other versions may also be affected.
Exploit / POC
Ulead COOL 3D Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
Attackers must trick a user into opening a file on a remote WebDAV or SMB share to exploit this issue.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Attackers must trick a user into opening a file on a remote WebDAV or SMB share to exploit this issue.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
Ulead COOL 3D Multiple DLL Loading Arbitrary Code Execution Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].