CVE-2009-1743 describes a directory traversal vulnerability in InstallHFZ.exe within Pinnacle Hollywood Effects 6, a component of Pinnacle Studio 12. This flaw allows remote attackers to create or overwrite arbitrary files on a user's system by embedding "..\ " sequences in filenames within specially crafted .hfz archive files. With a CVSS score of 9.3, this vulnerability is critical, enabling complete compromise (confidentiality, integrity, availability) through a network-based attack requiring moderate user interaction. While not actively exploited in the wild, public exploit code exists, and its high FAUCET Risk Score of 96/100 indicates significant potential impact, though it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12CPE matchmatch criteria | cpe:2.3:a:pinnaclesys:pinnacle_studio:12:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.