DLL Pre-Loading Vulnerability in Symantec VIP Access for Desktop
CVE-2017-6329

7.8HIGH

Key Information:

Vendor
Symantec Corporation
Status
Vip Access For Desktop
Vendor
CVE Published:
21 August 2017

Summary

Symantec VIP Access for Desktop versions before 2.2.4 are vulnerable to a DLL Pre-Loading flaw. This vulnerability occurs when the application attempts to load a dynamic link library (DLL) during execution. If an attacker can place a malicious DLL in the application's search path, the application may inadvertently load and execute this untrusted DLL, allowing potential execution of harmful code with the application's permissions. This can lead to unauthorized actions or data leakage under the context of the application.

Affected Version(s)

VIP Access for Desktop prior to 2.2.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.