First published: Fri Aug 04 2017(Updated: )
Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dashlane |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11657 is considered a moderate severity vulnerability.
Fixing CVE-2017-11657 involves ensuring that no unauthorized WINHTTP.dll files are present in the %APPDATA%\Dashlane directory.
CVE-2017-11657 affects Dashlane installed on Windows platforms.
CVE-2017-11657 requires local access to exploit, meaning it cannot be exploited remotely.
Local users with access to the affected Dashlane installation are at risk for CVE-2017-11657.