CVE-2017-2248: Chitora Lhaz+
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Untrusted search path vulnerability in Installer of Lhaz+ version 3.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected products
- Chitora Lhaz+: up to and including 3.4.0
Published 2017-07-17. Last modified 2026-06-17.