Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-7293


The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1, 1.3.2, 1.4, 1.4.1, 1.4.2, 1.4.3, and 1.4.4 and Dolby Audio X3 (DAX3) 1.0 and 1.1. An example affected driver is Realtek Audio Driver 6.0.1.7898 on a Lenovo P50.


Published

2017-04-26T05:59:00.167

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dolby dolby_audio_x2 1.0 Yes
Application dolby dolby_audio_x2 1.0.1 Yes
Application dolby dolby_audio_x2 1.1 Yes
Application dolby dolby_audio_x2 1.1.1 Yes
Application dolby dolby_audio_x2 1.2 Yes
Application dolby dolby_audio_x2 1.3 Yes
Application dolby dolby_audio_x2 1.3.1 Yes
Application dolby dolby_audio_x2 1.3.2 Yes
Application dolby dolby_audio_x2 1.4 Yes
Application dolby dolby_audio_x2 1.4.1 Yes
Application dolby dolby_audio_x2 1.4.2 Yes
Application dolby dolby_audio_x2 1.4.3 Yes
Application dolby dolby_audio_x2 1.4.4 Yes
Application dolby dolby_audio_x3 1.0 Yes
Application dolby dolby_audio_x3 1.1 Yes

References