CVE-2019-12177: Critical severity htc viveport vulnerability
Published Jun 3, 2019
·Updated
Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges via DLL hijacking.
Affected Software
1 affected component
HTC Viveport<1.0.0.36
Event History
Jun 3, 2019
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12177?
CVE-2019-12177 is a vulnerability that allows local attackers to escalate privileges via DLL hijacking in HTC VIVEPORT before version 1.0.0.36.
2
What is the severity of CVE-2019-12177?
CVE-2019-12177 has a severity rating of 7.8 (critical).
3
How does CVE-2019-12177 work?
CVE-2019-12177 allows local attackers to escalate privileges by exploiting insecure directory permissions in ViveportDesktopService and performing DLL hijacking.
4
Which software versions are affected by CVE-2019-12177?
CVE-2019-12177 affects HTC VIVEPORT versions up to, but excluding, 1.0.0.36.
5
How can CVE-2019-12177 be fixed?
To fix CVE-2019-12177, it is recommended to update HTC VIVEPORT to version 1.0.0.36 or later.