ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched from a directory where an attacker has already created a Trojan horse dwmapi.dll file.
References
Link Resource
http://www.securityfocus.com/bid/102044 Third Party Advisory VDB Entry
https://packetstormsecurity.com/files/145202/Amazon-Audible-DLL-Hijacking.html Issue Tracking Third Party Advisory VDB Entry
https://twitter.com/LionHeartRoxx/status/936338288314540032 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-12-06T05:00:00

Updated: 2017-12-06T10:57:01

Reserved: 2017-11-30T00:00:00


Link: CVE-2017-17069

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-12-06T05:29:00.193

Modified: 2017-12-20T20:30:51.640


Link: CVE-2017-17069

JSON object: View

cve-icon Redhat Information

No data.

CWE