CVE-2018-6547 - CERT CVE
ID CVE-2018-6547
Sažetak plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains an HTTP message parsing function that takes a user-defined path and writes non-user controlled data as SYSTEM to the file when the extract_files parameter is used. This occurs without properly authenticating the user.
Reference
CVSS
Base: 9.4
Impact: 9.2
Exploitability:10.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE COMPLETE COMPLETE
CVSS vektor AV:N/AC:L/Au:N/C:N/I:C/A:C
Zadnje važnije ažuriranje 21-05-2018 - 17:09
Objavljeno 13-04-2018 - 16:29