vendor:
PolarisOffice 2017 v8
by:
John Page (aka hyp3rlinx)
7.8
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: PolarisOffice 2017 v8
Affected Version From: PolarisOffice 2017 v8
Affected Version To: PolarisOffice 2017 v8
Patch Exists: YES
Related CWE: CVE-2018-12589
CPE: a:polaris_office:polaris_office_2017_v8
Metasploit:
N/A
Platforms Tested: Windows
2018
PolarisOffice 2017 v8 Remote Code Execution
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse "puiframeworkproresenu.dll" file in the current working directory, due to a search order flaw vulnerability. An attacker can create a 32bit DLL named "puiframeworkproresenu.dll" and put any .PDF or .PPTX file or whatever that is configured to open in Polaris Office in same directory as the above DLL. When the document is opened, the arbitrary DLL will execute on victims system.
Mitigation:
Update to the latest version of Polaris Office 2017 v8