Untrusted Search Path Vulnerability in PDF Digital Signature Plugin by G2
CVE-2017-2233

7.8HIGH

What is CVE-2017-2233?

The PDF Digital Signature Plugin from G2 contains an untrusted search path vulnerability in its installer, present in version G2.30 and earlier, that may allow an attacker to exploit a Trojan horse DLL located in an untrusted directory. This flaw can enable unauthorized access or elevation of privileges, posing significant security risks to affected systems.

Affected Version(s)

Installer of PDF Digital Signature Plugin (G2.30) and earlier, distributed till June 29, 2017

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.