CVE-2017-11657: High severity dashlane vulnerability
Published Aug 4, 2017
·Updated
Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane directory.
Affected Software
1 affected component
DashLane Dashlane Windows
Event History
Aug 4, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11657?
CVE-2017-11657 is considered a moderate severity vulnerability.
2
How do I fix CVE-2017-11657?
Fixing CVE-2017-11657 involves ensuring that no unauthorized WINHTTP.dll files are present in the %APPDATA%\Dashlane directory.
3
What platforms are affected by CVE-2017-11657?
CVE-2017-11657 affects Dashlane installed on Windows platforms.
4
Can CVE-2017-11657 be exploited remotely?
CVE-2017-11657 requires local access to exploit, meaning it cannot be exploited remotely.
5
What users are at risk for CVE-2017-11657?
Local users with access to the affected Dashlane installation are at risk for CVE-2017-11657.