VDB
CVE-2017-3196
CVE-2017-3196
PUBLISHED
CVSS 7.800000190734863 HIGH
PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver's receipt of network packets. Local attackers can exploit this issue to execute arbitrary code with SYSTEM privileges.
EPSS 0.25% · 48.4th percentile
Risk Scores
CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.25%
48.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Printing Communications Assoc., Inc. (PCAUSA) | ASUS PCE-AC56 WLAN Card Utilities | Unknown |
| rawether_project | rawether |
Timeline
- Dec 15, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- http://blog.rewolf.pl/blog/?p=1778 url
- https://www.itsecuritynews.info/vuln-printing-communications-association-rawether-cve-2017-3196-local-privilege-escalation-vulnerability/ url
- VU#600671 third-party-advisory
- 96993 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2017-3196 advisory
- https://www.itsecuritynews.info/vuln-printing-communications-association-rawether-cve-2017-3196-local-privilege-escalation-vulnerability url