Summary
The host is installed with Soda PDF and is prone to insecure library loading vulnerability.
Impact
Successful exploitation will allow local attacker to execute arbitrary code and conduct DLL hijacking attacks.
Impact Level: System/Application
Solution
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore.
General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
Insight
The flaw is due to the application loading libraries (dwmapi.dll or api-ms-win-core-localregistry-l1-1-0.dll) in an insecure manner.
Affected
Soda PDF version 5.1.183.10520, Other versions may also be affected.
Detection
Get the installed version with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2013-3485 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Apple Safari Webkit Multiple Vulnerabilities - June13 (Mac OS X)
- Adobe Reader Plugin Signature Bypass Vulnerability (Mac OS X)
- Adobe Digital Edition Information Disclosure Vulnerability (Windows)
- Apple Safari Secure Cookie Security Bypass Vulnerability (Mac OS X)
- Apple Safari JavaScript Implementation Information Disclosure Vulnerability (Windows)