CVE-2017-15088 is a critical vulnerability affecting MIT Kerberos 5 (krb5) versions up to 1.15.2, specifically within the plugins/preauth/pkinit/pkinit_crypto_openssl.c component. It stems from improper handling of Distinguished Name (DN) fields, which can lead to a buffer overflow and application crash, or arbitrary code execution, when processing untrusted X.509 data. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no public exploits or Metasploit modules are available, and it's not listed in the KEV catalog, community discussion is notably high, suggesting awareness despite the lack of active exploitation intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.15.2CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.