Home→Descriptions→SA42798
| Secunia ID | |
| CVE-ID | |
| Release Date |
04 Jan 2011 |
| Last Change |
17 Jan 2011 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
ImgBurn 2.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been discovered in ImgBurn, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to the application loading libraries (e.g. dwmapi.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a CUE file located on a remote WebDAV or SMB share. Successful exploitation allows execution of arbitrary code. The vulnerability is confirmed in version 2.5.4.0. Other versions may also be affected. |
| Solution |
Update to version 2.5.5.0. |
| Reported by |
d3c0der |
| Original Advisory |
ImgBurn: d3c0der: |