First published: Fri Jul 07 2017(Updated: )
Untrusted search path vulnerability in Installer of QuickTime for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime Player | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2218 is classified with a medium severity level, as it poses a risk of privilege escalation through untrusted search paths.
To fix CVE-2017-2218, ensure that you are using the latest version of QuickTime for Windows, as updates may address this vulnerability.
The potential impacts of CVE-2017-2218 include unauthorized access and privilege escalation for an attacker using a malicious DLL.
CVE-2017-2218 affects various versions of Apple QuickTime Player installed on Windows systems.
CVE-2017-2218 is not typically exploited remotely, as it usually requires local access to the system to introduce the malicious DLL.