CVE-2017-13878 is a local privilege escalation vulnerability affecting macOS before version 10.13.2, specifically within the Intel Graphics Driver component. An attacker can exploit this flaw to bypass memory-read restrictions or trigger a denial of service via an out-of-bounds read, leading to a system crash. With a CVSS score of 7.1 (High), it requires local access but has low attack complexity, potentially leading to high confidentiality impact and high availability impact. While there is no evidence of active exploitation in the wild and minimal community discussion, a proof-of-concept exploit exists on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.13.2CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.