ntfs-3g: Modprobe influence vulnerability via environment variables
Vulnerability Description
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-0358
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Jann Horn of Google Project Zero
References
- https://security.gentoo.org/glsa/201702-10
- https://www.debian.org/security/2017/dsa-3780
- https://www.exploit-db.com/exploits/41240/
- https://www.exploit-db.com/exploits/41356/
- http://www.securityfocus.com/bid/95987
- https://marc.info/?l=oss-security&m=148594671929354&w=2
- http://www.openwall.com/lists/oss-security/2017/02/04/1
Affected Vendor
ntfs-3g
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.