Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2017-6329 |
CWE-ID | CWE-426 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
VIP Access for Desktop Client/Desktop applications / Other client software |
Vendor | Broadcom |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU7995
Risk: Low
CVSSv4.0: 4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2017-6329
CWE-ID:
CWE-426 - Untrusted Search Path
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists due to untrusted search path element. A local attacker can load a specially crafted .dll file, gain root access and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Update to version 2.2.4.
VIP Access for Desktop: 1.0.1 - 2.2.3
CPE2.3https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&...
Q & A
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.