CVE-2017-7293
Summary
| CVE | CVE-2017-7293 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-26 05:59:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1, 1.3.2, 1.4, 1.4.1, 1.4.2, 1.4.3, and 1.4.4 and Dolby Audio X3 (DAX3) 1.0 and 1.1. An example affected driver is Realtek Audio Driver 6.0.1.7898 on a Lenovo P50. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dolby | Dolby Audio X2 | 1.0 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.0.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.1.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.3 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.4 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.0 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.0.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.1.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.3 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.4 | All | All | All |
| Application | Dolby | Dolby Audio X3 | 1.0 | All | All | All |
| Application | Dolby | Dolby Audio X3 | 1.1 | All | All | All |
| Application | Dolby | Dolby Audio X3 | 1.0 | All | All | All |
| Application | Dolby | Dolby Audio X3 | 1.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Realtek Audio Driver 6.0.1.7898 (Windows 10) - Dolby Audio X2 Service Privilege Escalation - Windows local Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| 1075 - Windows: Dolby Audio X2 Service EoP - project-zero - Monorail | MISC | bugs.chromium.org | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.