CVE-2017-2802
Summary
| CVE | CVE-2017-2802 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-24 19:29:00 UTC |
| Updated | 2018-06-13 17:02:00 UTC |
| Description | An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment variable will lead to privilege escalation. An attacker with local access to vulnerable system can exploit this vulnerability. |
Risk And Classification
Problem Types: CWE-426
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Precision Optimizer | 3.5.5.0 | All | All | All |
| Application | Dell | Precision Optimizer | 3.5.5.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 99360 | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| TALOS-2016-0247 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence | MISC | www.talosintelligence.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.