Adobe Device Central & Pixel Bender Toolkit Insecure Library Loading Vulnerability
RISK: Medium Risk
A vulnerability has been discovered in Adobe Device Central and Adobe Pixel Bender Toolkit, which can be exploited by malicious people to compromise a user's system.
1. The vulnerability is caused due to the application loading libraries (e.g. ibfs32.dll and amt_cdb.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a ADCP file located on a remote WebDAV or SMB share.
2. The vulnerability is caused due to the application bundling a vulnerable version of the Intel TBB library, which loads libraries (e.g. tbbmalloc.dll) in an insecure manner and due to the "sniffer_gpu.exe" utility loading libraries (e.g. d3d10.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a PBK file located on a remote WebDAV or SMB share.
Impact
- Remote Code Execution
System / Technologies affected
- Adobe Device Central CS4 2.x
- Adobe Pixel Bender Toolkit 2.x
Solutions
Do not open untrusted files.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with