CVE-2017-12653: High severity 360totalsecurity 360 Total Security vulnerability
Published Aug 7, 2017
·Updated
360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory.
Affected Software
1 affected component
360totalsecurity 360 Total Security<=9.0.0.1202
Event History
Aug 7, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12653?
CVE-2017-12653 has been classified as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2017-12653?
To fix CVE-2017-12653, update to a version of 360 Total Security greater than 9.0.0.1202.
3
What type of vulnerability is CVE-2017-12653?
CVE-2017-12653 is a privilege escalation vulnerability that can be exploited via a malicious Shcore.dll file.
4
What software is affected by CVE-2017-12653?
CVE-2017-12653 affects 360 Total Security versions prior to 9.0.0.1202.
5
Is there a public exploit for CVE-2017-12653?
Yes, there are public demonstrative exploits available for CVE-2017-12653 that illustrate the privilege escalation vector.