CVE-2017-3141: Windows service and uninstall paths are not quoted when BIND is installed
The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2017-3141?
CVE-2017-3141 is a vulnerability in the BIND installer on Windows that uses an unquoted service path, enabling a local user to achieve privilege escalation.
Which versions of BIND are affected by CVE-2017-3141?
BIND versions 9.2.6-P2 to 9.2.9, 9.3.2-P1 to 9.3.6, 9.4.0 to 9.8.8, 9.9.0 to 9.9.10, 9.10.0 to 9.10.5, and 9.11.0 to 9.11.1 are affected by CVE-2017-3141.
What is the severity of CVE-2017-3141?
The severity of CVE-2017-3141 is high, with a CVSS score of 7.8.
How can this vulnerability be exploited?
This vulnerability can be exploited by a local user with appropriate file system permissions to escalate their privileges on the system.
Where can I find more information about CVE-2017-3141?
You can find more information about CVE-2017-3141 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/99089), [SecurityTracker](http://www.securitytracker.com/id/1038693), and [ISC Knowledge Base](https://kb.isc.org/docs/aa-01496).