Vulnerability Name:

CVE-2014-8393 (CCN-100056)

Assigned:2014-10-22
Published:2015-01-13
Updated:2018-10-09
Summary:DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-427
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-8393

Source: MISC
Type: Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/129922/Corel-Software-DLL-Hijacking.html

Source: FULLDISC
Type: Mailing List, Third Party Advisory
20150112 Corel Software DLL Hijacking

Source: SECUNIA
Type: Permissions Required
62210

Source: CCN
Type: Corel Web site
PaintShop

Source: MISC
Type: Third Party Advisory
http://www.coresecurity.com/advisories/corel-software-dll-hijacking

Source: BUGTRAQ
Type: UNKNOWN
20150112 Corel Software DLL Hijacking

Source: BID
Type: Third Party Advisory, VDB Entry
72005

Source: CCN
Type: BID-72005
Multiple Corel Products 'wintab32.dll' DLL Loading Arbitrary Code Execution Vulnerability

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1031522

Source: XF
Type: UNKNOWN
corel-cve20148393-code-exec(100056)

Source: CCN
Type: Packet Storm Security [01-13-2015]
Corel Software DLL Hijacking

Vulnerable Configuration:Configuration 1:
  • cpe:/a:corel:coreldraw:x7:*:*:*:*:*:*:*
  • OR cpe:/a:corel:coreldraw_photo_paint:x7:*:*:*:*:*:*:*
  • OR cpe:/a:corel:paint_shop_pro:x7:*:*:*:*:*:*:*
  • OR cpe:/a:corel:painter:2015:*:*:*:*:*:*:*
  • OR cpe:/a:corel:pdf_fusion:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:corel:paintshop_pro_x5:15.2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:corel:painter:2015:*:*:*:*:*:*:*
  • OR cpe:/a:corel:pdf_fusion:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    corel coreldraw x7
    corel coreldraw photo paint x7
    corel paint shop pro x7
    corel painter 2015
    corel pdf fusion -
    corel paintshop pro x5 15.2.0.2
    corel painter 2015
    corel pdf fusion *