CVE-2017-7293

HIGH

Dolby DAX2/DAX3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1, 1.3.2, 1.4, 1.4.1, 1.4.2, 1.4.3, and 1.4.4 and Dolby Audio X3 (DAX3) 1.0 and 1.1. An example affected driver is Realtek Audio Driver 6.0.1.7898 on a Lenovo P50.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Google Security Research · textlocalwindows
https://www.exploit-db.com/exploits/41933
github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2017-7293.md
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2017-7293.md

Scores

CVSS v3 7.8
EPSS 0.0206
EPSS Percentile 84.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (15)
dolby/dolby_audio_x2 1.0
dolby/dolby_audio_x2 1.0.1
dolby/dolby_audio_x2 1.1
dolby/dolby_audio_x2 1.1.1
dolby/dolby_audio_x2 1.2
dolby/dolby_audio_x2 1.3
dolby/dolby_audio_x2 1.3.1
dolby/dolby_audio_x2 1.3.2
dolby/dolby_audio_x2 1.4
dolby/dolby_audio_x2 1.4.1
... and 5 more
Published Apr 26, 2017
Tracked Since Feb 18, 2026