PT-2017-17002 · Symantec · Symantec Vip Access Desktop

Publicado

2017-08-21

·

Atualizado

2019-10-03

·

CVE-2017-6329

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Symantec VIP Access for Desktop versions prior to 2.2.4
Description The issue occurs due to a DLL Pre-Loading vulnerability, where an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. The exploitation of the issue manifests as a simple file write (or potentially an over-write) which results in a foreign executable running under the context of the application.
Recommendations For Symantec VIP Access for Desktop versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue. As a temporary workaround, consider restricting the application's ability to load external DLLs to minimize the risk of exploitation.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6329

Produtos afetados

Symantec Vip Access Desktop