PT-2017-1628 · Microsoft · Windows 7+4

Hyp3Rlinx

+1

·

Published

2017-03-14

·

Updated

2017-08-16

·

CVE-2017-0045

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows DVD Maker versions in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2
Description The issue is related to the improper parsing of crafted .msdvd files by Windows DVD Maker, allowing attackers to obtain information that could be used to compromise a target system. This could potentially lead to the exploitation of the system through specially crafted applications.
Recommendations For Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00781
CVE-2017-0045

Affected Products

Windows
Windows 7
Windows Dvd Maker
Windows Server 2008
Windows Vista