Dolby Audio X2 (DAX2) unauthorized vulnerability

Source: Internet
Author: User
Tags file permissions lenovo

Lenovo security announcement: LEN-4884

Potential impact: local unauthorized access vulnerability

Severity: high

Abstract: A file permission vulnerability has been found in the Dolby Audio X2 (DAX2) software utility. This vulnerability allows local users to run files with system-level permissions.

Description:

Dolby Audio X2 (DAX2) is an industry-standard software program developed by Dolby Laboratories for many vendors. With this software, users can optimize their system's Audio performance. Some Lenovo systems that are pre-installed with Windows 10 include this program.

A file permission vulnerability has been found in the Dolby DAX2 application programming interface (API). This vulnerability allows local users to run files with system-level permissions.

Solution:

Measures should be taken for self-protection:

Lenovo is working with Dolby to release an updated version of this driver, which will include fixes for this vulnerability. For customers who are worried about this issue, Lenovo has released a batch file that fixes insecure permissions for Windows Dolby driver files. By running the batch file as an administrator, the Dolby Audio X2 driver will no longer be affected. You can obtain the batch processing file in bbs/mobiles/dolby_acl_rm.bat ">.

In addition, you can also delete the access permissions to the "authenticated users" group from the following directory to manually delete the file permissions with vulnerabilities.

For 32-bit Windows: C: Program Files (x86) DolbyDolby DAX2DAX2_API

For 64-bit Windows: C: Program FilesDolbyDolby DAX2DAX2_API

To perform the preceding operations, right-click the folder listed above and select "file properties"> "security" in the DAX2_API directory, alternatively, run the following command in the administrator command prompt window:

For 32-bit Windows: icacls "C: Program Files (x86) DolbyDolby DAX2DAX2_API"/remove "Authenticated Users"

For 64-bit Windows: icacls "C: Program FilesDolbyDolby DAX2DAX2_API"/remove "Authenticated Users"

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.