DLL Hijacking Vulnerability in Yandex Browser for Desktop
CVE-2017-7327

7.8HIGH

Key Information:

Vendor
CVE Published:
19 January 2018

What is CVE-2017-7327?

The Yandex Browser for Desktop prior to version 17.4.1 is susceptible to a DLL Hijacking vulnerability. This flaw arises from the implementation of an untrusted search path for critical DLL files including dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll, and profapi.dll. Exploitation of this vulnerability allows attackers to potentially execute arbitrary code, posing a risk to user data and system integrity. Users are advised to update to the latest version to mitigate this threat.

Affected Version(s)

Yandex Browser for Desktop All versions prior to version 17.4.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.