Skip to main content

Adobe Device Central & Pixel Bender Toolkit Insecure Library Loading Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 8 Dec 2010 5877 Views

RISK: Medium Risk

A vulnerability has been discovered in Adobe Device Central and Adobe Pixel Bender Toolkit, which can be exploited by malicious people to compromise a user's system.

1. The vulnerability is caused due to the application loading libraries (e.g. ibfs32.dll and amt_cdb.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a ADCP file located on a remote WebDAV or SMB share.

2. The vulnerability is caused due to the application bundling a vulnerable version of the Intel TBB library, which loads libraries (e.g. tbbmalloc.dll) in an insecure manner and due to the "sniffer_gpu.exe" utility loading libraries (e.g. d3d10.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a PBK file located on a remote WebDAV or SMB share.


Impact

  • Remote Code Execution

System / Technologies affected

  • Adobe Device Central CS4 2.x
  • Adobe Pixel Bender Toolkit 2.x

Solutions

Do not open untrusted files.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link