CVE-2017-1711: High severity IBM Notes vulnerability
Published Feb 13, 2018
·Updated
IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.
Affected Software
10 affected components
IBM Notes=8.5.0.0
IBM Notes=8.5.1.0
IBM Notes=8.5.2.0
IBM Notes=8.5.3.0
IBM Notes=9.0.0.0
IBM Notes=9.0.1.0
IBM Client Application Access=1.0.1.0
IBM Client Application Access=1.0.1.1
IBM Client Application Access=1.0.1.1-interim_fix_1
IBM Client Application Access=1.0.1.2-interim_fix_1
Remediation
Patch Available
Patch Available
Event History
Feb 13, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1711?
The severity of CVE-2017-1711 is high with a score of 7.8.
2
How does CVE-2017-1711 affect IBM iNotes?
CVE-2017-1711 affects IBM iNotes versions 8.5 and 9.0.
3
How can CVE-2017-1711 be exploited?
CVE-2017-1711 can be exploited by misleading the iNotes SUService into running malicious code from a DLL masquerading as a Windows DLL in the temp directory.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-1711?
The Common Weakness Enumeration (CWE) ID for CVE-2017-1711 is 426.
5
How can I fix CVE-2017-1711?
To fix CVE-2017-1711, it is recommended to apply the necessary patches and updates provided by IBM.