Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2018-17612

HIGH severity · CVSS 7.5 · CWE-295
7.5CVSS HIGH

Summary

Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for several years, even if the HeadSetup product is uninstalled. NOTE: a vulnerability-assessment approach must check all Windows systems for CA certificates with a CN of 127.0.0.1 or SennComRootCA, and determine whether those certificates are unwanted.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactNone
Integrity impactHigh
Availability impactNone
Exploit probability (EPSS)7%

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products we track (3)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180029 ↗