CVE-2018-17170: Code Injection
Published Jun 28, 2019
·Updated
Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
Affected Software
1 affected component
Teamwire Teamwire>=1.5.1<1.9.0
Event History
Jun 28, 2019
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17170?
The severity of CVE-2018-17170 is classified as critical due to its potential for remote code execution.
2
How do I fix CVE-2018-17170?
To address CVE-2018-17170, update the Teamwire Desktop Client to version 1.9.0 or later.
3
What does CVE-2018-17170 affect?
CVE-2018-17170 affects the Teamwire Desktop Client versions 1.5.1 through 1.8.x on Windows.
4
What type of vulnerability is CVE-2018-17170?
CVE-2018-17170 is a code injection vulnerability that can lead to remote code execution.
5
When was CVE-2018-17170 disclosed?
CVE-2018-17170 was disclosed in November 2018, highlighting the need for immediate updates to impacted software.