Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .xpr or .DESIGN file, aka Expression Design Insecure Library Loading Vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Expression_design | Microsoft | - (including) | - (including) |
Expression_design | Microsoft | –sp1 (including) | –sp1 (including) |
Expression_design | Microsoft | 2 (including) | 2 (including) |
Expression_design | Microsoft | 3 (including) | 3 (including) |
Expression_design | Microsoft | 4 (including) | 4 (including) |