CVE-2017-1087 is a local privilege escalation and denial-of-service vulnerability affecting FreeBSD 10.x versions prior to 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24. It allows a malicious user within a jail to read and modify POSIX shared memory objects created by other jails or the host system due to globally scoped named paths. This could lead to applications executing injected malicious content, resulting in a denial of service or local privilege escalation. The vulnerability has a CVSSv3 score of 7.8 (High), indicating a low attack complexity and requiring low privileges, with high impacts on confidentiality, integrity, and availability. While the EPSS score is low, the FAUCET Risk Score is 56/100. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage has been identified for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.