CVE-2017-11672

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
13/06/2018
Last modified:
07/08/2018

Description

The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double quotes around the opcualds.exe executable path, which might allow local users to gain privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opcfoundation:local_discovery_server:*:*:*:*:*:*:*:* 1.03.367 (excluding)