VulnerabilityModified
CVE-2017-11421
gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue.
HIGH 7.8EPSS 0.63%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- gnome-exe-thumbnailer project/gnome-exe-thumbnailer
- Source
- cve@mitre.org
References
- http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.htmlThird Party Advisory
- http://www.securityfocus.com/bid/99922
- https://bugs.debian.org/868705Issue Tracking, Third Party Advisory
- https://github.com/gnome-exe-thumbnailer/gnome-exe-thumbnailer/commit/1d8e3102dd8fd23431ae6127d14a236da6b4a4a5Issue Tracking, Patch, Third Party Advisory
- http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.htmlThird Party Advisory
- http://www.securityfocus.com/bid/99922
- https://bugs.debian.org/868705Issue Tracking, Third Party Advisory
- https://github.com/gnome-exe-thumbnailer/gnome-exe-thumbnailer/commit/1d8e3102dd8fd23431ae6127d14a236da6b4a4a5Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.