[Japanese] | |
JVNDB-2017-000197 | |
Installer of Photo Collection PC Software provided by NTT DOCOMO, INC. may insecurely load Dynamic Link Libraries and invoke executable files | |
Overview | |
Photo Collection PC Software provided by NTT DOCOMO, INC. contains an issue with the search paths for DLL/executable files, which may lead to insecurely loading Dynamic Link Libraries and invoking executable files (CWE-427). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 7.8 (High) [IPA Score]
CVSS V2 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
| |
Affected Products | |
| |
NTT DOCOMO, INC. | |
| |
Impact | |
This vulnerability can be exploited when the following condition is met. If this vulnerability is exploited, an arbitrary code may be executed with the privilege of the user invoking the installer. | |
Solution | |
[Use the latest installer] | |
Vendor Information | |
NTT DOCOMO, INC. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2017/08/22 |
Date First Published | 2017/08/22 |
Date Last Updated | 2018/02/28 |