PT-2017-17086 · F Secure · F-Secure Software Updater
Published
2017-03-11
·
Updated
2017-03-14
·
CVE-2017-6466
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
F-Secure Software Updater version 2.20
Description
The issue allows man-in-the-middle attackers to replace downloaded files with their own executable, which will be executed under the SYSTEM account. This is because the software downloads installation packages over plain http and does not perform file integrity validation after download. In automatic mode, the software checks for digital signatures by default but does not verify the author of the signature. In manual mode, no signature check is performed.
Recommendations
For F-Secure Software Updater version 2.20, consider disabling the automatic installation of updates and manually verify the digital signature and its author before installing any updates. As a temporary workaround, restrict the use of the Software Updater until a secure version is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F-Secure Software Updater