Untrusted Search Path Vulnerability in DocuWorks by Fuji Xerox
CVE-2017-10848

7.8HIGH

Key Information:

What is CVE-2017-10848?

The vulnerability involves an untrusted search path in the installers for DocuWorks and DocuWorks Viewer Light, which allows attackers to execute malicious code by placing a Trojan horse DLL in an undisclosed directory. This flaw can serve as a vector for privilege escalation, enabling attackers to gain unauthorized access to system resources, potentially compromising the integrity of the affected systems.

Affected Version(s)

Installer for DocuWorks 8.0.7 and earlier

Installer for DocuWorks Viewer Light published in Jul 2017 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.