CVE-2017-17069: Critical severity Amazon Audible vulnerability
Published Dec 6, 2017
·Updated
ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched from a directory where an attacker has already created a Trojan horse dwmapi.dll file.
Affected Software
2 affected components
Amazon Audible<november2017
Microsoft Windows
Event History
Dec 6, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17069?
CVE-2017-17069 has been classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2017-17069?
To mitigate CVE-2017-17069, users should update to a version of Amazon Audible released after November 2017.
3
Who is affected by CVE-2017-17069?
CVE-2017-17069 affects users of Amazon Audible for Windows versions released before November 2017.
4
What type of attack does CVE-2017-17069 involve?
CVE-2017-17069 involves a DLL hijacking attack that allows execution of malicious code.
5
What is the impact of CVE-2017-17069?
The impact of CVE-2017-17069 can lead to unauthorized access and control over the affected system.