PT-2017-12912 · Akeo Consulting · Rufus

Wdormann

·

Published

2017-10-18

·

Updated

2019-10-09

·

CVE-2017-13083

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Akeo Consulting Rufus versions prior to 2.17.1187
Description The issue concerns inadequate validation of the integrity of updates downloaded over HTTP, allowing an attacker to convince a user to execute arbitrary code.
Recommendations For versions prior to 2.17.1187, update to version 2.17.1187 or later to resolve the issue.

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-13083

Affected Products

Rufus