← Back

CVE-2017-3210

nvd nist
Published: Jul 24, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe with NT AUTHORITY/SYSTEM permissions. This component is also read/writable by all Authenticated Users. This allows local authenticated attackers to run arbitrary code with SYSTEM privileges. The following applications have been identified by Portrait Displays as affected: Fujitsu DisplayView Click: Version 6.0 and 6.01. The issue was fixed in Version 6.3. Fujitsu DisplayView Click Suite: Version 5. The issue is addressed by patch in Version 5.9. HP Display Assistant: Version 2.1. The issue was fixed in Version 2.11. HP My Display: Version 2.0. The issue was fixed in Version 2.1. Philips Smart Control Premium: Versions 2.23, 2.25. The issue was fixed in Version 2.26.

Affected (8)

Show all products
1 product
Portrait Display Sdk
2 products
Displayview Click
Displayview Click Suite
2 products
Display Assistant
My Display
1 product
Smart Control Premium
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.30 to 2.34
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fujitsu
Version 6.01
Version 6.0
Version 5.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.1
Version 2.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Philips
Version 2.23
Version 2.25

References (4)

Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: cret@cert.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.