PT-2017-1500 · Adobe · Shockwave

Publicado

2017-03-14

·

Atualizado

2017-07-17

·

CVE-2017-2983

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Shockwave versions 12.2.7.197 and earlier
Description The issue is related to an insecure library loading (DLL hijacking) vulnerability. This vulnerability is associated with the unreliable search for critical resources. Successful exploitation could lead to escalation of privilege, allowing a remote attacker to elevate their privileges.
Recommendations For Adobe Shockwave versions 12.2.7.197 and earlier, consider restricting access to critical system resources to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the vulnerable library loading functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-00645
CVE-2017-2983

Produtos afetados

Shockwave