CVE-2017-11742
Dashboard / Vulnerabilities / CVE-2017-11742
CVE-2017-11742
Published: 30 Jul 2017Last Modified: 8 Jul 2026
Summary:
Details: The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacking.
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- c4446687cfc6c5fd7f6371aeaf24c69402a3589e
Fixed -None
Affected versions
2.2.1
2.2.2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
