JVN#09769017
Multiple Fuji Xerox products may insecurely load Dynamic Link Libraries
Overview
Multiple Fuji Xerox products may insecurely load Dynamic Link Libraries.
Products Affected
CVE-2017-10848
- Installer for DocuWorks 8.0.7 and earlier
- Installer for DocuWorks Viewer Light published in Jul 2017 and earlier
- Self-extracting document generated by DocuWorks 8.0.7 and earlier
- Installer of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:04 UTC.)
- Installer of PostScript® Driver + Additional Feature Plug-in + PPD File for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:10 UTC.)
- Installer of XPS Print Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 3 Nov 2017 23:48 UTC.)
- Installer of ART EX Direct FAX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 26 May 2017 07:44 UTC.)
- Installer of Setting Restore Tool for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 25 Aug 2015 08:51 UTC.)
- Installer for ContentsBridge Utility for Windows 7.4.0 and earlier
Description
Installers of multiple products, and DocuWorks self-extracting documents provided by Fuji Xerox Co.,Ltd. contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).
Impact
- Arbitrary code may be executed with the privilege of the administrative user invoking the installer - CVE-2017-10848, CVE-2017-10850, CVE-2017-10851
- Arbitrary code may be executed with the privilege of the user invoking the self-extracting document generated by DocuWorks - CVE-2017-10849
Solution
CVE-2017-10848, CVE-2017-10850, CVE-2017-10851
Use the latest installer
Use the latest installer according to the information provided by the developer.
CVE-2017-10849
Update the Software
Update to the latest version according to the information provided by the developer.
Apply a Workaround
The self-extracting document generator function is not included in the latest version of the software.
When invoking the DocuWorks self-extracting document file, place the document (.exe
) file in a newly created empty folder.
For more information, refer to the information provided by the developer.
Vendor Status
Vendor | Status | Last Update | Vendor Notes |
---|---|---|---|
Fuji Xerox Co.,Ltd. | Vulnerable | 2021/04/07 | Fuji Xerox Co.,Ltd. website |
References
-
Japan Vulnerability Note JVNTA#91240916
Insecure DLL Loading and Command Execution Issues on Many Windows Application Programs
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Comment
This analysis assumes that the user is tricked into placing a malicious DLL file prepared by an attacker in a specific folder.
Credit
Eili Masami of Tachibana Lab. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2017-10848 |
CVE-2017-10849 |
|
CVE-2017-10850 |
|
CVE-2017-10851 |
|
JVN iPedia |
JVNDB-2017-000219 |
Update History
- 2021/04/07
- Fuji Xerox Co.,Ltd. update status
- 2021/04/09
- The hyperlink URL under [Solution] was updated