{"id":"CVE-2017-11421","details":"gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the \"Bad Taste\" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.","modified":"2026-08-27T08:18:36.560053Z","published":"2017-07-18T19:29:00.193Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/99922"},{"type":"ADVISORY","url":"http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html"},{"type":"REPORT","url":"https://bugs.debian.org/868705"},{"type":"FIX","url":"https://github.com/gnome-exe-thumbnailer/gnome-exe-thumbnailer/commit/1d8e3102dd8fd23431ae6127d14a236da6b4a4a5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/exe-thumbnailer/exe-thumbnailer","events":[{"introduced":"0"},{"last_affected":"400b8063797cefe36fc018ae82de7b1946060032"},{"fixed":"1d8e3102dd8fd23431ae6127d14a236da6b4a4a5"}],"database_specific":{"cpe":"cpe:2.3:a:gnome-exe-thumbnailer_project:gnome-exe-thumbnailer:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.9.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.9.4","0.9.3-0ubuntu1","0.9-0ubuntu2","0.9-0ubuntu1","0.8-0ubuntu1","0.7-0ubuntu1","0.6-0ubuntu1","0.5-0ubuntu1","0.4-0ubuntu1","0.3-0ubuntu1","0.2","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11421.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}