PT-2018-13917 · Prezi · Prezi Next
Published
2018-09-17
·
Updated
2019-10-03
·
CVE-2018-17137
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Prezi Next version 1.3.101.11
Description
The issue concerns a potential bypass of intended access restrictions. Prezi Next is designed to create HTML5 presentations, but it has SE DEBUG PRIVILEGE on Windows, which could be exploited by attackers.
Recommendations
For Prezi Next version 1.3.101.11, consider restricting the use of SE DEBUG PRIVILEGE to minimize the risk of exploitation until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Prezi Next