7.8
CVE-2017-3210
- EPSS 0.05%
- Veröffentlicht 24.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:25:02
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution
Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe with NT AUTHORITY/SYSTEM permissions. This component is also read/writable by all Authenticated Users. This allows local authenticated attackers to run arbitrary code with SYSTEM privileges. The following applications have been identified by Portrait Displays as affected: Fujitsu DisplayView Click: Version 6.0 and 6.01. The issue was fixed in Version 6.3. Fujitsu DisplayView Click Suite: Version 5. The issue is addressed by patch in Version 5.9. HP Display Assistant: Version 2.1. The issue was fixed in Version 2.11. HP My Display: Version 2.0. The issue was fixed in Version 2.1. Philips Smart Control Premium: Versions 2.23, 2.25. The issue was fixed in Version 2.26.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Portrait ≫ Portrait Display Sdk Version >= 2.30 < 2.34
Fujitsu ≫ Displayview Click Version6.0
Fujitsu ≫ Displayview Click Version6.01
Fujitsu ≫ Displayview Click Suite Version5.0
Hp ≫ Display Assistant Version2.1
Hp ≫ My Display Version2.0
Philips ≫ Smart Control Premium Version2.23
Philips ≫ Smart Control Premium Version2.25
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.151 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.