« Volver al listado

CVE-2017-2176

Estado: ModificadaAlta (7.8)—

Untrusted search path vulnerability in screensaver installers (jasdf_01.exe, jasdf_02.exe, jasdf_03.exe, jasdf_04.exe, jasdf_05.exe, scramble_setup.exe, clock_01_setup.exe, clock_02_setup.exe) available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-2176",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE",
          "product": "jasdf_01.exe",
          "versions": [
            {
              "status": "affected",
              "version": "available prior to May 25, 2017"
            }
          ]
        },
        {
          "vendor": "JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE",
          "product": "jasdf_02.exe",
          "versions": [
            {
              "status": "affected",
              "version": "available prior to May 25, 2017"
            }
          ]
        },
        {
          "vendor": "JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE",
          "product": "jasdf_03.exe",
          "versions": [
            {
              "status": "affected",
              "version": "available prior to May 25, 2017"
            }
          ]
        },
        {
          "vendor": "JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE",
          "product": "jasdf_04.exe",
          "versions": [
            {
              "status": "affected",
              "version": "available prior to May 25, 2017"
            }
          ]
        },
        {
          "vendor": "JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE",
          "product": "jasdf_05.exe",
          "versions": [
            {
              "status": "affected",
              "version": "available prior to May 25, 2017"
            }
          ]
        },
        {
          "vendor": "JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE",
          "product": "scramble_setup.exe",
          "versions": [
            {
              "status": "affected",
              "version": "available prior to May 25, 2017"
            }
          ]
        },
        {
          "vendor": "JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE",
          "product": "clock_01_setup.exe",
          "versions": [
            {
              "status": "affected",
              "version": "available prior to May 25, 2017"
            }
          ]
        },
        {
          "vendor": "JAPAN AIR SELF DEFENSE FORCE, MINISTRY OF DEFENSE",
          "product": "clock_02_setup.exe",
          "versions": [
            {
              "status": "affected",
              "version": "available prior to May 25, 2017"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-06-09T16:29:01.390",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN41185163/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.mod.go.jp/asdf/information/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.securityfocus.com/bid/98823",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN41185163/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mod.go.jp/asdf/information/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/98823",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-426"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Untrusted search path vulnerability in screensaver installers (jasdf_01.exe, jasdf_02.exe, jasdf_03.exe, jasdf_04.exe, jasdf_05.exe, scramble_setup.exe, clock_01_setup.exe, clock_02_setup.exe) available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de ruta (path) de búsqueda no confiable en archivos instaladores de salvapantallas (jasdf_01.exe, jasdf_02.exe, jasdf_03.exe, jasdf_04.exe, jasdf_05.exe, scramble_setup.exe, clock_01_setup.exe, clock_02_setup.exe) disponibles antes del 25 de mayo de 2017, permite alcanzar privilegios por medio de un archivo DLL de tipo caballo de Troya en un directorio no especificado."
    }
  ],
  "lastModified": "2026-06-17T01:15:41.520",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jasdf:screensavers:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E3EC0FB-D3B1-4703-BDC5-DB4BDFE8AB6A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}