#VU6386 Incorrect default permissions in Portrait Display SDK - CVE-2017-3210
Published: April 25, 2017
Portrait Display SDK
Portrait Displays, Inc.
Description
The vulnerability allows a local user to elevate his privileges.
The vulnerability exists due to Portrait Displays SDK is installed with world-writable permissions and runs the component pdiservice.exe under context of NT AUTHORITY/SYSTEM. A local user can overwrite the affected file and execute arbitrary code on the system with elevated privileges.
Successful exploitation of the vulnerability maty allow a local user to escalate privileges and compromise affected system.