CVE Intelligence
Skip to main content

CVE-2017-10850

CVE-2017-10850 Vulnerability Analysis & Exploit Intelligence

Untrusted search path vulnerability in Installers of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:04 UTC.), PostScript? Driver + Additional Feature Plug-in + PPD File for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:10 UTC.), XPS Print Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 3 Nov 2017 23:48 UTC.), ART EX Direct FAX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 26 May 2017 07:44 UTC.), Setting Restore Tool for ApeosPort-VI…

Published Updated Sources: cvelistV5, jpcert

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

1%

chance of exploitation in 30 days

Affects

fuji xerox co

10 products listed

CVSS base

Unscored

no source published a base score

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (1)

Products (10)

installer of art ex driver for apeosport vi c7771 c6671 c5571 c4471 c3371 c2271installer of art ex driver for docucentre vi c7771 c6671 c5571 c4471 c3371 c2271installer of postscript driver additional feature plug in ppd file for apeosport vi c7771 c6671 c5571 c4471 c3371 c2271installer of postscript driver additional feature plug in ppd file for docucentre vi c7771 c6671 c5571 c4471 c3371 c2271installer of xps print driver for apeosport vi c7771 c6671 c5571 c4471 c3371 c2271installer of xps print driver for docucentre vi c7771 c6671 c5571 c4471 c3371 c2271installer of art ex direct fax driver for apeosport vi c7771 c6671 c5571 c4471 c3371 c2271installer of art ex direct fax driver for docucentre vi c7771 c6671 c5571 c4471 c3371 c2271installer of setting restore tool for apeosport vi c7771 c6671 c5571 c4471 c3371 c2271installer of setting restore tool for docucentre vi c7771 c6671 c5571 c4471 c3371 c2271

Detection

Read off the CVSS vector and the weakness class. Starting points, not rules we have tested.

  • Search application, proxy, and WAF logs for requests touching /C6671/C5571/C4471/C3371/C2271.

References

2 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.