Untrusted Search Path Vulnerability in Lhaz Self-Extracting Archive Files
CVE-2017-2247

7.8HIGH

Key Information:

Vendor
CVE Published:
17 July 2017

What is CVE-2017-2247?

An untrusted search path vulnerability exists in Lhaz self-extracting archive files created by versions 2.4.0 and earlier. This issue enables attackers to exploit the system by placing a malicious DLL in an unspecified directory, which can facilitate unauthorized privilege escalation. Users of the impacted versions should take immediate action to mitigate the risk associated with this vulnerability.

Affected Version(s)

Self-extracting archive files created by Lhaz version 2.4.0 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.