CVE-2017-2208

HIGH

Installer of Electronic Tendering and Bid Opening System < 06112017 - Untrusted Search Path

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in Installer of Electronic tendering and bid opening system available prior to June 12, 2017 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry third-party-advisory x_refsource_jvn
https://jvn.jp/en/jp/JVN27198823/index.html

Scores

CVSS v3 7.8
EPSS 0.0137
EPSS Percentile 68.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (2)
Acquisition, Technology & Logistics Agency/Installer of electronic tendering and bid opening system available prior to June 12, 2017
acquisition_technology_and_logistics_agency/installer_of_electronic_tendering < 06112017
Published Jul 07, 2017
Tracked Since Feb 18, 2026