PT-2022-7846 · Filezilla · Filezilla Client
Cyril Vallicari
·
Published
2022-07-18
·
Updated
2022-07-25
·
CVE-2016-15003
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FileZilla Client version 3.17.0.0
Description
A vulnerability has been found in the Installer component, specifically affecting the file C:Program FilesFileZilla FTP Clientuninstall.exe. The manipulation leads to an unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations
For version 3.17.0.0, consider updating to a newer version to mitigate the risk, as the current version is affected by the unquoted search path vulnerability. As a temporary workaround, restrict access to the uninstall.exe file to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filezilla Client