PT-2018-3796 · Yandex · Yandex Browser

Publicado

2018-01-19

·

Atualizado

2018-02-01

·

CVE-2017-7327

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yandex Browser versions prior to 17.4.1
Description The issue exists due to the lack of checks for loading paths of certain DLL files, including dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll, and profapi.dll. This can allow an attacker to execute arbitrary code.
Recommendations For versions prior to 17.4.1, update to version 17.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable DLL files until a patch is available.

Correção

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-03581
CVE-2017-7327

Produtos afetados

Yandex Browser