Adobe RoboHelp 10 Unspecified Memory Corruption (APSB13-024)

critical Nessus Plugin ID 70352

Synopsis

An application on the remote host is affected by a memory corruption vulnerability.

Description

The Adobe RoboHelp 10 install on the remote Windows host includes a DLL (MDBMS.dll) that is earlier than 10.0.1.294. It is, therefore, reportedly affected by an unspecified memory corruption vulnerability.
Successful exploitation of this issue could allow an attacker to execute arbitrary code on the affected system.

Solution

Update the MDBMS.dll file as discussed in Adobe Security Bulletin APSB13-24.

See Also

https://helpx.adobe.com/security/products/robohelp/apsb13-24.html

Plugin Details

Severity: Critical

ID: 70352

File Name: robohelp_apsb13-24.nasl

Version: 1.6

Type: local

Agent: windows

Family: Windows

Published: 10/10/2013

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:adobe:robohelp

Required KB Items: SMB/Registry/Enumerated, SMB/Adobe_RoboHelp/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2013

Vulnerability Publication Date: 10/8/2013

Reference Information

CVE: CVE-2013-5327

BID: 62887