ID

VAR-201708-0802


CVE

CVE-2017-2289


TITLE

Installer of Qua station connection tool for Windows may insecurely load Dynamic Link Libraries

Trust: 0.8

sources: JVNDB: JVNDB-2017-000191

DESCRIPTION

Untrusted search path vulnerability in Installer of Qua station connection tool for Windows version 1.00.03 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. Qua station provided KDDI CORPORATION is a 4G LTE photostrage. Qua station connection tool is used to view data saved on Qua station from a PC and/or save data on a PC. Eili Masami of Tachibana Lab. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.Arbitrary code may be executed with the privilege of the user invoking the installer. A remote attacker can exploit this vulnerability to obtain permissions by means of a malicious DLL in the directory

Trust: 1.71

sources: NVD: CVE-2017-2289 // JVNDB: JVNDB-2017-000191 // VULHUB: VHN-110492

AFFECTED PRODUCTS

vendor:kddimodel:qua stationscope:eqversion:1.00.03

Trust: 1.6

vendor:kddimodel:qua station connection toolscope:eqversion:for windows version 1.00.03

Trust: 0.8

sources: JVNDB: JVNDB-2017-000191 // CNNVD: CNNVD-201708-972 // NVD: CVE-2017-2289

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-2289
value: HIGH

Trust: 1.0

IPA: JVNDB-2017-000191
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201708-972
value: CRITICAL

Trust: 0.6

VULHUB: VHN-110492
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-2289
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

IPA: JVNDB-2017-000191
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-110492
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-2289
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.0

IPA: JVNDB-2017-000191
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-110492 // JVNDB: JVNDB-2017-000191 // CNNVD: CNNVD-201708-972 // NVD: CVE-2017-2289

PROBLEMTYPE DATA

problemtype:CWE-426

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-110492 // JVNDB: JVNDB-2017-000191 // NVD: CVE-2017-2289

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201708-972

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201708-972

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-000191

PATCH

title:Qua stationurl:https://www.au.com/mobile/product/4glte-photostorage/quastation/

Trust: 0.8

title:KDDI Qua station connection tool for windows Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=74226

Trust: 0.6

sources: JVNDB: JVNDB-2017-000191 // CNNVD: CNNVD-201708-972

EXTERNAL IDS

db:JVNid:JVN81659403

Trust: 2.5

db:NVDid:CVE-2017-2289

Trust: 2.5

db:JVNDBid:JVNDB-2017-000191

Trust: 0.8

db:CNNVDid:CNNVD-201708-972

Trust: 0.7

db:VULHUBid:VHN-110492

Trust: 0.1

sources: VULHUB: VHN-110492 // JVNDB: JVNDB-2017-000191 // CNNVD: CNNVD-201708-972 // NVD: CVE-2017-2289

REFERENCES

url:https://jvn.jp/en/jp/jvn81659403/index.html

Trust: 2.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-2289

Trust: 0.8

url:https://jvn.jp/en/ta/jvnta91240916/index.html

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-2289

Trust: 0.8

sources: VULHUB: VHN-110492 // JVNDB: JVNDB-2017-000191 // CNNVD: CNNVD-201708-972 // NVD: CVE-2017-2289

SOURCES

db:VULHUBid:VHN-110492
db:JVNDBid:JVNDB-2017-000191
db:CNNVDid:CNNVD-201708-972
db:NVDid:CVE-2017-2289

LAST UPDATE DATE

2025-04-20T23:34:19.295000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-110492date:2017-08-22T00:00:00
db:JVNDBid:JVNDB-2017-000191date:2018-02-14T00:00:00
db:CNNVDid:CNNVD-201708-972date:2017-08-28T00:00:00
db:NVDid:CVE-2017-2289date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-110492date:2017-08-18T00:00:00
db:JVNDBid:JVNDB-2017-000191date:2017-08-08T00:00:00
db:CNNVDid:CNNVD-201708-972date:2017-08-28T00:00:00
db:NVDid:CVE-2017-2289date:2017-08-18T13:29:00.513