PT-2017-12222 · Vit · Vit Spider Player

Ye Yint Min Thu Htut

·

Published

2017-07-30

·

Updated

2017-08-09

·

CVE-2017-11748

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VIT Spider Player version 2.5.3
Description The issue allows for DLL hijacking via a Trojan horse file, specifically targeting dwmapi.dll, olepro32.dll, dsound.dll, or AUDIOSES.dll. This can occur due to an untrusted search path.
Recommendations For VIT Spider Player version 2.5.3, consider restricting access to the mentioned DLL files until a patch is available. As a temporary workaround, avoid using the application in environments where untrusted files may be present. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11748

Affected Products

Vit Spider Player