PT-2017-11564 · I-Filter · I-Filter

Eili Masami

·

Published

2017-09-15

·

Updated

2017-09-22

·

CVE-2017-10860

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions i-filter 6.0 installer version before 23 Aug 2017
Description The issue allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory, due to an untrusted search path vulnerability.
Recommendations For i-filter 6.0 installer version before 23 Aug 2017, ensure the timestamp of code signing is updated to 23 Aug 2017 (JST) or later to prevent exploitation.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10860

Affected Products

I-Filter