PT-2017-17086 · F Secure · F-Secure Software Updater

Published

2017-03-11

·

Updated

2017-03-14

·

CVE-2017-6466

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions F-Secure Software Updater version 2.20
Description The issue allows man-in-the-middle attackers to replace downloaded files with their own executable, which will be executed under the SYSTEM account. This is because the software downloads installation packages over plain http and does not perform file integrity validation after download. In automatic mode, the software checks for digital signatures by default but does not verify the author of the signature. In manual mode, no signature check is performed.
Recommendations For F-Secure Software Updater version 2.20, consider disabling the automatic installation of updates and manually verify the digital signature and its author before installing any updates. As a temporary workaround, restrict the use of the Software Updater until a secure version is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6466

Affected Products

F-Secure Software Updater