Microsoft Expression Design Insecure Library Loading

Strike ID:
E12-02201
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2012

Description

This strike exploits the insecure way that libraries are searched for by Microsoft Expression Design that could result in the loading of malicious files located in the same directory as files with recognized extensions.

CVE

Bid