CVE-2017-20018

MEDIUM

XAMPP 7.1.1-0-VC14 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely.

References (2)

Core 2
Core References
Exploit, Mitigation, Third Party Advisory, VDB Entry x_refsource_misc
https://packetstormsecurity.com/files/142406/xampp-dllhijack.txt
Third Party Advisory x_refsource_misc
https://vuldb.com/?id.100950

Scores

CVSS v3 6.3
EPSS 0.0058
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-427
Status published
Products (1)
apachefriends/xampp 7.1.1-0-vc14
Published Jun 09, 2022
Tracked Since Feb 18, 2026