CVE-2017-14971
Last modified
CVE-2017-14971 is a vulnerability of currently unknown severity. Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-controller server. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-controller server. In one specific scenario, the attacker provides an Excel spreadsheet, and the attacker-controller server receives the victim's NetNTLMv2 hash.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Infocuscorp | Infocus Mondopad | 2.2.08 |
References
- https://raw.githubusercontent.com/badbiddy/Vulnerability-Disclosure/master/InFocus%20Mondopad%20%3C%202.2.08%20-%20CVE-2017-14971Exploit, Mitigation, Third Party Advisory
- https://raw.githubusercontent.com/badbiddy/Vulnerability-Disclosure/master/InFocus%20Mondopad%20%3C%202.2.08%20-%20CVE-2017-14971Exploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14971?
How severe is CVE-2017-14971?
How do I fix CVE-2017-14971?
Are you affected by CVE-2017-14971?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
