DLL Pre-Loading Vulnerability in Symantec VIP Access for Desktop
CVE-2017-6329
7.8HIGH
Key Information:
- Vendor
- Symantec Corporation
- Status
- Vip Access For Desktop
- Vendor
- CVE Published:
- 21 August 2017
Summary
Symantec VIP Access for Desktop versions before 2.2.4 are vulnerable to a DLL Pre-Loading flaw. This vulnerability occurs when the application attempts to load a dynamic link library (DLL) during execution. If an attacker can place a malicious DLL in the application's search path, the application may inadvertently load and execute this untrusted DLL, allowing potential execution of harmful code with the application's permissions. This can lead to unauthorized actions or data leakage under the context of the application.
Affected Version(s)
VIP Access for Desktop prior to 2.2.4
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved