Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution.
CWE-276: Incorrect Default Permissions - CVE-2017-3210
A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe with NT AUTHORITY/SYSTEM permissions. This component is also read/writable by all Authenticated Users. This allows local authenticated attackers to run arbitrary code with SYSTEM privileges.
A local authenticated (non-privileged) attacker can run arbitrary code with SYSTEM privileges.
Apply an update
Ensure that affected applications are updated to the most recent versions.
Manually remove unsafe permissions
Thanks to Werner Schober of SEC Consult for reporting this vulnerability.
This document was written by Trent Novelly.
|Date First Published:||2017-04-25|
|Date Last Updated:||2017-04-25 16:58 UTC|