Incorrect default permissions in Portrait Display SDK - CVE-2017-3210

 

Incorrect default permissions in Portrait Display SDK - CVE-2017-3210

Published: April 25, 2017


Vulnerability identifier: #VU6386
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3210
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to elevate his privileges.

The vulnerability exists due to Portrait Displays SDK is installed with world-writable permissions and runs the component pdiservice.exe under context of NT AUTHORITY/SYSTEM. A local user can overwrite the affected file and execute arbitrary code on the system with elevated privileges.

Successful exploitation of the vulnerability maty allow a local user to escalate privileges and compromise affected system.


Affected software

Portrait Display SDK
HP My Display
HP Display Assistant
Philips Smart Control Premium
Fujitsu DisplayView Click Suite
Fujitsu DisplayView Click

How to mitigate CVE-2017-3210

Install update from vendor's website.


External References

Related Security Bulletins