CVE-2017-2802
CVE-2017-2802
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Apr 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment variable will lead to privilege escalation. An attacker with local access to vulnerable system can exploit this vulnerability.
Affected products
dell · DellWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →