PT-2017-1500 · Adobe · Shockwave

Published

2017-03-14

·

Updated

2017-07-17

·

CVE-2017-2983

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Shockwave versions 12.2.7.197 and earlier
Description The issue is related to an insecure library loading (DLL hijacking) vulnerability. This vulnerability is associated with the unreliable search for critical resources. Successful exploitation could lead to escalation of privilege, allowing a remote attacker to elevate their privileges.
Recommendations For Adobe Shockwave versions 12.2.7.197 and earlier, consider restricting access to critical system resources to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the vulnerable library loading functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00645
CVE-2017-2983

Affected Products

Shockwave