Untrusted Search Path Vulnerability in QuickTime Installer by Apple
CVE-2017-2218
7.8HIGH
Summary
An untrusted search path vulnerability exists in the Installer of QuickTime for Windows. This flaw could allow an attacker to gain elevated privileges if a malicious DLL is placed in a location that the installer accesses. This kind of attack could enable the execution of arbitrary code or manipulation of sensitive operations, highlighting the importance of secure file handling and system configurations to mitigate such risks.
Affected Version(s)
Installer of QuickTime for Windows all versions
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved