CVE-2017-6455
published 2017-03-27CVE-2017-6455: NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.
PriorityP430high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.48%
38.6th percentile
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.
Affected
97 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra | — | — |
| debian | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_debian7.0LOW
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-6455: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 7.0
CVE-2017-6455 [HIGH] CVE-2017-6455: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6455
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
Red Hat
ntp: Privileged execution of User Library code
vendor_redhat·2017-03-21·CVSS 7.0
CVE-2017-6455 [HIGH] ntp: Privileged execution of User Library code
ntp: Privileged execution of User Library code
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.
Statement: This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2017-6455: ntp - NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local use...
vendor_debian·2017·CVSS 7.0
CVE-2017-6455 [HIGH] CVE-2017-6455: ntp - NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local use...
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.
Scope: local
bullseye: resolved
GHSA
GHSA-xcr3-hhwm-r755: NTP before 4
ghsa_unreviewed·2022-05-17
CVE-2017-6455 [HIGH] CWE-94 GHSA-xcr3-hhwm-r755: NTP before 4
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.
No detection rules found.
No public exploits indexed.
http://support.ntp.org/bin/view/Main/NtpBug3384http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.securityfocus.com/bid/97074http://www.securitytracker.com/id/1038123http://www.securitytracker.com/id/1039427https://support.apple.com/HT208144http://support.ntp.org/bin/view/Main/NtpBug3384http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.securityfocus.com/bid/97074http://www.securitytracker.com/id/1038123http://www.securitytracker.com/id/1039427https://support.apple.com/HT208144
2017-03-27
Published