Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2017-3210 Details

Description

Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe with NT AUTHORITY/SYSTEM permissions. This component is also read/writable by all Authenticated Users. This allows local authenticated attackers to run arbitrary code with SYSTEM privileges. The following applications have been identified by Portrait Displays as affected: Fujitsu DisplayView Click: Version 6.0 and 6.01. The issue was fixed in Version 6.3. Fujitsu DisplayView Click Suite: Version 5. The issue is addressed by patch in Version 5.9. HP Display Assistant: Version 2.1. The issue was fixed in Version 2.11. HP My Display: Version 2.0. The issue was fixed in Version 2.1. Philips Smart Control Premium: Versions 2.23, 2.25. The issue was fixed in Version 2.26.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.kb.cert.org/vuls/id/219739 CVEThird Party AdvisoryUS Government Resource
https://www.securityfocus.com/bid/98006 CVEThird Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/219739 [email protected]Third Party AdvisoryUS Government Resource
https://www.securityfocus.com/bid/98006 [email protected]Third Party AdvisoryVDB Entry

Weakness Enumeration

CWE-IDCWE NameSource
CWE-16Configuration[email protected]
CWE-276Incorrect Default Permissions[email protected]

Affected Products

ProductVersions

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2017-3210
NVD Published Date:
Jul 24, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2017-3210 Details - Not Deferred