CVE-2016-4288: High severity myvesta vulnerability
Published Jan 6, 2017
·Updated
A local privilege escalation vulnerability exists in BlueStacks App Player. The BlueStacks App Player installer creates a registry key with weak permissions that allows users to execute arbitrary programs with SYSTEM privileges.
Affected Software
1 affected component
BlueStacks BlueStacks=2.1.3.5650
Event History
Jan 6, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-4288?
CVE-2016-4288 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2016-4288?
To mitigate CVE-2016-4288, update BlueStacks App Player to the latest version where the vulnerability has been addressed.
3
Which versions of BlueStacks are affected by CVE-2016-4288?
BlueStacks App Player version 2.1.3.5650 is specifically affected by CVE-2016-4288.
4
What can attackers do with CVE-2016-4288?
Attackers can exploit CVE-2016-4288 to execute arbitrary programs with SYSTEM privileges on affected systems.
5
Is CVE-2016-4288 a critical vulnerability?
While CVE-2016-4288 is a serious local privilege escalation vulnerability, its criticality depends on the context of its exploitation.