IBM Security Bulletin: IBM Client Application Access Privilege escalation in IBM Notes Smart Update Service

IBM iNotes SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM Plans to address this vulnerability by providing a fix.

CVE(s): CVE-2017-1711

Affected product(s) and affected version(s):

– IBM Client Application Access 1.0.1

– IBM Client Application Access 1.0.1.1

– IBM Client Application Access 1.0.1.1 Interim Fix 1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg22010774
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/134532

The post IBM Security Bulletin: IBM Client Application Access Privilege escalation in IBM Notes Smart Update Service appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2EdK9L8