CVE-2017-1591308.01.2018, 03:29The Installer in Whale allows DLL hijacking.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST7.8 HIGHLOCALLOWNONECVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 37%VendorProductVersionnavercorpwhale-𝑥= Vulnerable software versionsCommon Weakness EnumerationCWE-426 - Untrusted Search PathThe application searches for critical resources using an externally-supplied search path that can point to resources that are not under the application's direct control.Referenceshttps://bugbounty.whale.naver.com/en/halloffamehttps://cve.naver.com/detail/cve-2017-15913.htmlhttps://bugbounty.whale.naver.com/en/halloffamehttps://cve.naver.com/detail/cve-2017-15913.html