CVE-2017-6189

HIGH

Amazon Kindle for PC < 1.17.44183 - Untrusted Search Path DLL Hijacking

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in Amazon Kindle for PC before 1.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL in the current working directory of the Kindle Setup installer.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96476
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/Feb/71
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/141366/Amazon-Kindle-DLL-Hijacking.html

Scores

CVSS v3 7.3
EPSS 0.0010
EPSS Percentile 27.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (1)
amazon/kindle_for_pc < 1.17.44183
Published Mar 15, 2017
Tracked Since Feb 18, 2026