CVE-2017-7293
Summary
| CVE | CVE-2017-7293 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-26 05:59:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1, 1.3.2, 1.4, 1.4.1, 1.4.2, 1.4.3, and 1.4.4 and Dolby Audio X3 (DAX3) 1.0 and 1.1. An example affected driver is Realtek Audio Driver 6.0.1.7898 on a Lenovo P50. |
Risk And Classification
Primary CVSS: v3.0 7.8 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-502 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dolby | Dolby Audio X2 | 1.0 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.0.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.1.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.3.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.1 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.2 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.3 | All | All | All |
| Application | Dolby | Dolby Audio X2 | 1.4.4 | All | All | All |
| Application | Dolby | Dolby Audio X3 | 1.0 | All | All | All |
| Application | Dolby | Dolby Audio X3 | 1.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Realtek Audio Driver 6.0.1.7898 (Windows 10) - Dolby Audio X2 Service Privilege Escalation - Windows local Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| 1075 - Windows: Dolby Audio X2 Service EoP - project-zero - Monorail | af854a3a-2127-422b-91ae-364da2661108 | bugs.chromium.org | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.