CVE-2017-3092 Vulnerability Details

  /     /     /  

CVE-2017-3092 Metadata Quick Info

CVE Published: 20/06/2017 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: adobe | Vendor: n/a | Product: Adobe Digital Editions 4.5.4 and earlier.
Status : PUBLISHED

CVE-2017-3092 Description

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of editor control library functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Insecure Library Loading (DLL hijacking)
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).