PT-2017-12003 · Gnome · Gnome-Exe-Thumbnailer

Nils Dagsson Moskopp

·

Published

2017-07-18

·

Updated

2017-07-26

·

CVE-2017-11421

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gnome-exe-thumbnailer versions prior to 0.9.5
Description The issue is related to a VBScript Injection when generating thumbnails for MSI files. This can lead to a local attack if the victim uses the GNOME Files file manager and navigates to a directory containing a .msi file with VBScript code in its filename.
Recommendations For versions prior to 0.9.5, update to version 0.9.5 or later to resolve the issue. As a temporary workaround, consider avoiding the use of gnome-exe-thumbnailer for .msi files until a patch is applied. Restrict access to directories containing potentially malicious .msi files to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11421

Affected Products

Gnome-Exe-Thumbnailer