VDB
CVE-2017-0358
CVE-2017-0358
PUBLISHED
CVSS 7.800000190734863 HIGH
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
EPSS 2.19% · 81.7th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.19%
81.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | ntfs-3g | 0, 1:2014.2.15AR.3-3, 1:2015.3.14AR.1-1 |
Timeline
- Feb 1, 2017 CVE Published
- Feb 4, 2017 PoC Published
- Feb 14, 2017 PoC Published
- Feb 14, 2017 PoC Published
- May 29, 2018 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Sep 14, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Dec 29, 2021 EPSS Score
- Mar 2, 2022 EPSS Score
- May 4, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-0358 third-party-advisory
- https://ubuntu.com/security/notices/USN-3182-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-0358 third-party-advisory