CVE-2017-9046
PoC —CVSS 3.0
7.3 high
EPSS
<1%p45
Published
()
Modified
Description
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the desktop and executes arbitrary code in the DllMain function, then clicking on a mailto: link on a remote web page triggers the attack.
- Vendors
- pmail
- Products
- pegasus
- Weakness
- CWE-20
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.