{"api_version":"1","generated_at":"2026-07-23T04:22:45+00:00","cve":"CVE-2017-2802","urls":{"html":"https://cve.report/CVE-2017-2802","api":"https://cve.report/api/cve/CVE-2017-2802.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-2802","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-2802"},"summary":{"title":"CVE-2017-2802","description":"An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment variable will lead to privilege escalation. An attacker with local access to vulnerable system can exploit this vulnerability.","state":"PUBLIC","assigner":"talos-cna@cisco.com","published_at":"2018-04-24 19:29:00","updated_at":"2018-06-13 17:02:00"},"problem_types":["CWE-426"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/99360","name":"99360","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0247","name":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0247","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"TALOS-2016-0247 ||  Cisco Talos Intelligence Group - Comprehensive Threat Intelligence","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-2802","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-2802","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"2802","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dell","cpe5":"precision_optimizer","cpe6":"3.5.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"2802","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dell","cpe5":"precision_optimizer","cpe6":"3.5.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"talos-cna@cisco.com","DATE_PUBLIC":"2017-06-30T00:00:00","ID":"CVE-2017-2802","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Dell","version":{"version_data":[{"version_value":"Precision Tower 5810 with nvidia graphic cards. PPO Policy Processing Engine - FileVersion : 3.5.5.0 ati.dll ( PPO Monitoring Plugin ) - FileVersion : 3.5.5.0"}]}}]},"vendor_name":"dell"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment variable will lead to privilege escalation. An attacker with local access to vulnerable system can exploit this vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"dll hijiacking"}]}]},"references":{"reference_data":[{"name":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0247","refsource":"MISC","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0247"},{"name":"99360","refsource":"BID","url":"http://www.securityfocus.com/bid/99360"}]}},"nvd":{"publishedDate":"2018-04-24 19:29:00","lastModifiedDate":"2018-06-13 17:02:00","problem_types":["CWE-426"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dell:precision_optimizer:3.5.5.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"2802","Ordinal":"98941","Title":"CVE-2017-2802","CVE":"CVE-2017-2802","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"2802","Ordinal":"1","NoteData":"An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment variable will lead to privilege escalation. An attacker with local access to vulnerable system can exploit this vulnerability.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"2802","Ordinal":"2","NoteData":"2018-04-24","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"2802","Ordinal":"3","NoteData":"2018-04-25","Type":"Other","Title":"Modified"}]}}}