peter bassill · operator
$ cve CVE-2010-3153 JSON

CVE-2010-3153 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 13.6% (pctl 96)

Patch early

A public exploit exists.

Description

Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe InCopy CS5 7.0.2 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an .indl, .indp, .indt, or .inx file.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS13.56% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2010-08-27
Last modified2026-06-16

Affected (1)

VendorProduct
adobeindesign cs4

Public exploits

SourceTitleDate
exploit-dbAdobe InDesign CS4 - 'ibfs32.dll' DLL Hijacking2010-08-25

References

→ the Explorer  ·  watch your stack  ·  NVD