CVE-2017-7327: High severity yandex browser vulnerability
Published Jan 19, 2018
·Updated
Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll or profapi.dll.
Affected Software
1 affected component
Yandex Yandex Browser<=17.4.0.16
Event History
Jan 19, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7327?
CVE-2017-7327 has a critical severity rating due to the potential exploitation through DLL hijacking.
2
How do I fix CVE-2017-7327?
To fix CVE-2017-7327, update Yandex Browser to version 17.4.1 or later.
3
What are the affected components in CVE-2017-7327?
CVE-2017-7327 affects dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll, and profapi.dll due to an untrusted search path.
4
What versions of Yandex Browser are affected by CVE-2017-7327?
Yandex Browser versions prior to 17.4.1, including up to 17.4.0.16, are affected by CVE-2017-7327.
5
Can CVE-2017-7327 lead to unauthorized code execution?
Yes, CVE-2017-7327 can allow attackers to execute arbitrary code by exploiting the DLL hijacking vulnerability.