First published: Wed Mar 15 2017(Updated: )
Untrusted search path vulnerability in Amazon Kindle for PC before 1.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL in the current working directory of the Kindle Setup installer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Kindle for PC | <=1.17.44183 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6189 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2017-6189, users should update Amazon Kindle for PC to version 1.19 or later.
CVE-2017-6189 affects users of Amazon Kindle for PC versions prior to 1.19.
CVE-2017-6189 is associated with DLL hijacking attacks, allowing local users to execute malicious code.
CVE-2017-6189 cannot be exploited remotely; it requires local access to the system to conduct the attack.