ACDSee Ultimate CVE-2017-2886 Remote Code Execution Vulnerability



ACDSee Ultimate is prone to a remote code execution vulnerability.

An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will likely cause a denial-of-service condition.

Information

Bugtraq ID: 102133
Class: Input Validation Error
CVE: CVE-2017-2886

Remote: Yes
Local: No
Published: Dec 08 2017 12:00AM
Updated: Dec 12 2017 12:12AM
Credit: Piotr Bania of Cisco Talos.
Vulnerable: Acdsystems Ultimate 10.0.0.292
Acdsystems Ultimate 10


Not Vulnerable:

Exploit


The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.


Related Posts

Comments