Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jpg file.
2014-06-05T20:55:04.267
2025-04-12T10:46:40.837
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | corel | paintshop_pro_x5 | ≤ 15.2.0.2 | Yes |
Application | corel | paintshop_pro_x6 | ≤ 16.0.0.113 | Yes |