Insecure DLL loading in IBM iNotes - CVE-2017-1711
Published: February 12, 2018 / Updated: February 16, 2018
IBM iNotes
Detailed vulnerability description
The vulnerability exists due to insecure C++ .dll loading mechanism when opening files. A local attacker can place a file along with specially crafted .dll file on a remote SBM or WebDAV share and execute arbitrary code on the target system with system privileges.
Successful exploitation of the vulnerability may result in system compromise.