CVE-2017-10849: Critical severity fujixerox docuworks vulnerability
Published Sep 1, 2017
·Updated
Untrusted search path vulnerability in Self-extracting document generated by DocuWorks 8.0.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
1 affected component
Fujixerox Docuworks<=8.0.7
Event History
Sep 1, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-10849?
CVE-2017-10849 is classified as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2017-10849?
To fix CVE-2017-10849, update to DocuWorks version 8.0.8 or later.
3
What is CVE-2017-10849?
CVE-2017-10849 is an untrusted search path vulnerability in DocuWorks that allows privilege escalation through a Trojan horse DLL.
4
Which versions of DocuWorks are affected by CVE-2017-10849?
CVE-2017-10849 affects DocuWorks versions 8.0.7 and earlier.
5
Can CVE-2017-10849 be exploited remotely?
No, CVE-2017-10849 requires local access to exploit the untrusted search path vulnerability.