Altova DatabaseSpy 2011 "dwmapi.dll" DLL Loading Arbitrary Code Execution

  Bookmark
 and Share

Altova DatabaseSpy is a multiple database query, design, and database comparison tool. Altova DatabaseSpy 2011 is exposed to an issue that lets attackers execute arbitrary code. The issue arises because the application searches for the "dwmapi.dll" Dynamic Link Library file in the current working directory. Successful exploits will compromise the application in the context of the currently logged-in user.

Ref: http://blogs.technet.com/b/msrc/archive/2010/08/21/microsoft-security-advisory-2269637-released.aspx

10.50.33 - CVE: Not Available
Platform: Cross Platform