Lucene search

K
nvd[email protected]NVD:CVE-2017-2157
HistoryMay 12, 2017 - 6:29 p.m.

CVE-2017-2157

2017-05-1218:29:00
CWE-426
web.nvd.nist.gov
11

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

53.1%

Untrusted search path vulnerability in installers for The Public Certification Service for Individuals “The JPKI user’s software (for Windows 7 and later)” Ver3.1 and earlier, The Public Certification Service for Individuals “The JPKI user’s software (for Windows Vista)”, The Public Certification Service for Individuals “The JPKI user’s software” Ver2.6 and earlier that were available until April 27, 2017 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

Affected configurations

Nvd
Node
jpkithe_public_certification_service_for_individualsRange2.6
OR
jpkithe_public_certification_service_for_individualsRange3.1windows_7
OR
jpkithe_public_certification_service_for_individualsMatch-windows_vista
VendorProductVersionCPE
jpkithe_public_certification_service_for_individuals*cpe:2.3:a:jpki:the_public_certification_service_for_individuals:*:*:*:*:*:*:*:*
jpkithe_public_certification_service_for_individuals*cpe:2.3:a:jpki:the_public_certification_service_for_individuals:*:*:*:*:windows_7:*:*:*
jpkithe_public_certification_service_for_individuals-cpe:2.3:a:jpki:the_public_certification_service_for_individuals:-:*:*:*:windows_vista:*:*:*

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

53.1%

Related for NVD:CVE-2017-2157