4.6
CVSSv2

CVE-2017-11421

Published: 18/07/2017 Updated: 26/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 410
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

gnome-exe-thumbnailer prior to 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome-exe-thumbnailer project gnome-exe-thumbnailer

Vendor Advisories

Debian Bug report logs - #868705 gnome-exe-thumbnailer: CVE-2017-11421: Thumbnail generation for MSI files executes arbitrary VBScript Package: gnome-exe-thumbnailer; Maintainer for gnome-exe-thumbnailer is Debian Wine Team <debian-wine@listsdebianorg>; Source for gnome-exe-thumbnailer is src:exe-thumbnailer (PTS, buildd, popcon) ...
gnome-exe-thumbnailer before 095 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a msi file with VBScript code in its filename ...