PT-2017-9389 · Unknown · Winsparkle

Takashi Yoshikawa

·

Publicado

2017-06-09

·

Atualizado

2017-06-20

·

CVE-2016-7838

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WinSparkle versions prior to 0.5.3
Description The issue allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory. This is due to an untrusted search path vulnerability.
Recommendations For versions prior to 0.5.3, update to version 0.5.3 or later to resolve the issue.

Correção

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7838

Produtos afetados

Winsparkle