Untrusted Search Path Vulnerability in PrimeDrive Desktop Application by SoftBank
CVE-2017-2108

7.8HIGH

Key Information:

Vendor
CVE Published:
28 April 2017

What is CVE-2017-2108?

The PrimeDrive Desktop Application, developed by SoftBank, contains a vulnerability that allows remote attackers to execute arbitrary code through a Trojan horse dynamic-link library (DLL). This occurs because the application does not properly validate the search path for DLL files, enabling attackers to leverage this flaw to gain elevated privileges. Exploitation of this vulnerability can lead to unauthorized access and a myriad of security risks, emphasizing the need for stringent security measures.

Affected Version(s)

PrimeDrive Desktop Application version 1.4.3 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.