Untrusted Search Path Vulnerability in Amazon Kindle for PC
CVE-2017-6189

7.3HIGH

Key Information:

Vendor

Amazon

Vendor
CVE Published:
15 March 2017

What is CVE-2017-6189?

Amazon Kindle for PC prior to version 1.19 is susceptible to an untrusted search path vulnerability, which allows local users to execute arbitrary code. This security flaw enables the execution of a Trojan horse DLL placed in the current working directory of the Kindle Setup installer, leading to potential DLL hijacking attacks. Users should ensure they are using updated versions of the software to mitigate this risk.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.