CVE-2017-11462 is a critical double free vulnerability in MIT Kerberos 5, affecting Fedora and MIT Kerberos 5 products. This flaw allows unauthenticated attackers to achieve high impact on confidentiality, integrity, and availability through network-based attacks with low complexity, stemming from automatic security context deletion errors. Despite its critical CVSS score of 9.8, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in the KEV catalog. Furthermore, the vulnerability has received minimal community attention or media coverage, indicating a lack of active exploitation or public discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.14:*:*:*:*:*:*:* | ||
1.14CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.14:alpha1:*:*:*:*:*:* | ||
1.14CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.14:beta1:*:*:*:*:*:* | ||
1.14CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.14:beta2:*:*:*:*:*:* | ||
1.14.1CPE matchmatch criteria | cpe:2.3:a:mit:kerberos_5:1.14.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.