Untrusted Search Path Vulnerability in Qua Station Connection Tool for Windows
CVE-2017-2289

7.8HIGH

What is CVE-2017-2289?

The Qua Station Connection Tool for Windows version 1.00.03 contains an untrusted search path vulnerability that could allow an attacker to execute a Trojan horse DLL from an unspecified directory, potentially leading to unauthorized privilege escalation. This vulnerability underscores the importance of securing application installations and validating the integrity of the libraries they load.

Affected Version(s)

Installer of Qua station connection tool for Windows version 1.00.03

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.