Incorrect default permissions in Portrait Display SDK - CVE-2017-3210
Published: April 25, 2017
Vulnerability details
The vulnerability allows a local user to elevate his privileges.
The vulnerability exists due to Portrait Displays SDK is installed with world-writable permissions and runs the component pdiservice.exe under context of NT AUTHORITY/SYSTEM. A local user can overwrite the affected file and execute arbitrary code on the system with elevated privileges.
Successful exploitation of the vulnerability maty allow a local user to escalate privileges and compromise affected system.
Affected software
HP My Display
HP Display Assistant
Philips Smart Control Premium
Fujitsu DisplayView Click Suite
Fujitsu DisplayView Click