CVE-2017-3210 describes a vulnerability in applications utilizing the Portrait Displays SDK, versions 2.30 through 2.34, including products from Fujitsu, HP, and Philips. These applications default to insecure configurations, allowing local authenticated attackers to achieve arbitrary code execution with SYSTEM privileges due to the pdiservice.exe component running with excessive permissions and being writable by all Authenticated Users. The vulnerability has a CVSSv3 score of 7.8 (HIGH), indicating a local attack vector with low attack complexity and low privileges required, leading to high impacts on confidentiality, integrity, and availability. Its EPSS score is very low at 0.00053, suggesting a low probability of exploitation in the wild. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. While there is limited community discussion and media coverage, the vulnerability is not listed on the CISA KEV catalog or the Hot List, further indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.30, < 2.34CPE matchmatch criteria | cpe:2.3:a:portrait:portrait_display_sdk:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:fujitsu:displayview_click:6.0:*:*:*:*:*:*:* | ||
6.01CPE matchmatch criteria | cpe:2.3:a:fujitsu:displayview_click:6.01:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:fujitsu:displayview_click_suite:5.0:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:a:hp:display_assistant:2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.