Untrusted Search Path Vulnerability in QuickTime Installer by Apple
CVE-2017-2218

7.8HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
7 July 2017

Summary

An untrusted search path vulnerability exists in the Installer of QuickTime for Windows. This flaw could allow an attacker to gain elevated privileges if a malicious DLL is placed in a location that the installer accesses. This kind of attack could enable the execution of arbitrary code or manipulation of sensitive operations, highlighting the importance of secure file handling and system configurations to mitigate such risks.

Affected Version(s)

Installer of QuickTime for Windows all versions

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.