CVE-2017-15011 Information

Description

The named pipes in qtsingleapp in Qt 5.x as used in qBittorrent and SugarSync are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

https://hackinparis.com/data/slides/2017/2017_Cohen_Gil_The_forgotten_interface_Windows_named_pipes.pdf https://www.youtube.com/watch?v=m6zISgWPGGY

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

7.5

Share on: