CVE-2017-9046: Input Validation
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the desktop and executes arbitrary code in the DllMain function, then clicking on a mailto: link on a remote web page triggers the attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9046?
CVE-2017-9046 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2017-9046?
To mitigate CVE-2017-9046, ensure that the affected version of Pegasus Mail (v4.72) is updated to the latest version provided by the vendor.
What impact does CVE-2017-9046 have on my system?
CVE-2017-9046 allows an attacker to execute arbitrary code on your system if a malicious ssgp.dll is present locally.
What software is affected by CVE-2017-9046?
CVE-2017-9046 affects Pegasus Mail version 4.72 build 572.
Can I prevent CVE-2017-9046 from being exploited?
Prevent CVE-2017-9046 from being exploited by avoiding the execution of untrusted DLL files and regularly updating your software.