CVE-2017-17069

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
06/12/2017
Last modified:
20/04/2025

Description

ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched from a directory where an attacker has already created a Trojan horse dwmapi.dll file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amazon:audible:*:*:*:*:*:*:*:* november2017 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*