CVE-2017-12717
HIGHAdvantech Webaccess < 8.2 - Uncontrolled Search Path
Title source: ruleDescription
An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the application.
Scores
CVSS v3
7.8
EPSS
0.0067
EPSS Percentile
71.1%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
draft
Affected Products (1)
advantech/webaccess
< 8.2
Timeline
Published
Aug 30, 2017
Tracked Since
Feb 18, 2026