First published: Fri Jun 09 2017(Updated: )
Untrusted search path vulnerability in the installer of SaAT Personal ver.1.0.10.272 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
SaAT Personal | <=1.0.10.272 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2207 has a medium severity level due to its untrusted search path vulnerability that can lead to privilege escalation.
To fix CVE-2017-2207, update SaAT Personal to version 1.0.10.273 or later to ensure that the untrusted search path vulnerability is mitigated.
SaAT Personal versions 1.0.10.272 and earlier are affected by CVE-2017-2207.
CVE-2017-2207 enables privilege escalation attacks by allowing the execution of a Trojan horse DLL.
A potential workaround for CVE-2017-2207 is to prevent unauthorized access to directories that may be used for DLL placement.