SB2017042503 - Privilege escalation in Portrait Display SDK
Published: April 25, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect default permissions (CVE-ID: CVE-2017-3210)
The vulnerability allows a local user to elevate his privileges.
The vulnerability exists due to Portrait Displays SDK is installed with world-writable permissions and runs the component pdiservice.exe under context of NT AUTHORITY/SYSTEM. A local user can overwrite the affected file and execute arbitrary code on the system with elevated privileges.
Successful exploitation of the vulnerability maty allow a local user to escalate privileges and compromise affected system.
Remediation
Install update from vendor's website.