Untrusted Search Path Vulnerability in DocuWorks by Fuji Xerox
CVE-2017-10848
7.8HIGH
What is CVE-2017-10848?
The vulnerability involves an untrusted search path in the installers for DocuWorks and DocuWorks Viewer Light, which allows attackers to execute malicious code by placing a Trojan horse DLL in an undisclosed directory. This flaw can serve as a vector for privilege escalation, enabling attackers to gain unauthorized access to system resources, potentially compromising the integrity of the affected systems.
Affected Version(s)
Installer for DocuWorks 8.0.7 and earlier
Installer for DocuWorks Viewer Light published in Jul 2017 and earlier
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved