PT-2017-12222 · Vit · Vit Spider Player

Ye Yint Min Thu Htut

·

Publicado

2017-07-30

·

Atualizado

2017-08-09

·

CVE-2017-11748

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VIT Spider Player version 2.5.3
Description The issue allows for DLL hijacking via a Trojan horse file, specifically targeting dwmapi.dll, olepro32.dll, dsound.dll, or AUDIOSES.dll. This can occur due to an untrusted search path.
Recommendations For VIT Spider Player version 2.5.3, consider restricting access to the mentioned DLL files until a patch is available. As a temporary workaround, avoid using the application in environments where untrusted files may be present. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11748

Produtos afetados

Vit Spider Player