CVE-2017-2149
Summary
| CVE | CVE-2017-2149 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-28 16:59:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory. |
Risk And Classification
Problem Types: CWE-426
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Toshiba | Flashair | All | All | All | All |
| Application | Toshiba | Flashair | All | All | All | All |
| Application | Toshiba | Flashair | All | All | All | All |
| Application | Toshiba | Flashair | All | All | All | All |
| Application | Toshiba | Flashair | All | All | All | All |
| Application | Toshiba | Flashair | All | All | All | All |
| Application | Toshiba | Flashair | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Toshiba memory card installers DLL Loading Remote Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| JVN#05340816: Multiple installers of Toshiba memory card related software may insecurely load Dynamic Link Libraries | JVN | jvn.jp | Third Party Advisory, VDB Entry |
| (続報)NFC搭載SDメモリカード、FlashAir™、TransferJet™搭載SDメモリカードのWindows® 用ソフトウェアのインストーラにおけるDLL 読み込みに関する脆弱性について|東芝:パーソナルストレージ | MISC | www.toshiba-personalstorage.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.