This vulnerability may allow a malicious user to perform an attack that leverages social engineering to achieve remote code execution on the computer running the BlackBerry Desktop Manager.
Credit:
The information has been provided by OYXin .
Vulnerable Systems:
*BlackBerry Desktop Software version 5.0 and earlier (on all platforms), IBM Lotus Notes Intellisync functionality
Immune Systems:
*BlackBerry Device Software
*BlackBerry Enterprise Server
If the malicious user performs an attack designed to deceive the legitimate user into clicking a link to a web site that appears to be from a trusted source, and the legitimate user chooses to access that site from the computer that is running the BlackBerry Desktop Manager, the user might be deceived into browsing to a web page that the malicious user has designed to perform remote code execution using the legitimate user's privileges on the computer.
The BlackBerry Desktop Manager does not need to be running for a malicious user to exploit this vulnerability.
Vendor Status:
Blackberry had issued an update for this vulnerability