CVE-2014-8393 describes a DLL Hijacking vulnerability affecting multiple Corel products, including CorelDRAW X7, Photo-Paint X7, PaintShop Pro X7, Painter 2015, and PDF Fusion. This vulnerability carries a high CVSS score of 7.8, indicating a significant risk where an attacker could achieve high confidentiality, integrity, and availability impacts through a low-complexity local attack. While not listed on CISA's KEV catalog, there are public exploit examples on ExploitDB for older Corel versions demonstrating similar DLL hijacking techniques. Despite the high severity, there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage surrounding this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
x7CPE matchmatch criteria | cpe:2.3:a:corel:coreldraw:x7:*:*:*:*:*:*:* | ||
x7CPE matchmatch criteria | cpe:2.3:a:corel:coreldraw_photo_paint:x7:*:*:*:*:*:*:* | ||
x7CPE matchmatch criteria | cpe:2.3:a:corel:paint_shop_pro:x7:*:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:corel:painter:2015:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:corel:pdf_fusion:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.