High severity7.8NVD Advisory· Published Apr 26, 2017· Updated May 13, 2026
CVE-2017-7293
CVE-2017-7293
Description
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1, 1.3.2, 1.4, 1.4.1, 1.4.2, 1.4.3, and 1.4.4 and Dolby Audio X3 (DAX3) 1.0 and 1.1. An example affected driver is Realtek Audio Driver 6.0.1.7898 on a Lenovo P50.
Affected products
15cpe:2.3:a:dolby:dolby_audio_x2:1.0:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:dolby:dolby_audio_x2:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x2:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:dolby:dolby_audio_x3:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dolby:dolby_audio_x3:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:dolby:dolby_audio_x3:1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/41933/nvdExploitThird Party AdvisoryVDB Entry
- bugs.chromium.org/p/project-zero/issues/detailnvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.