CVE-2017-7138 is a low-severity vulnerability affecting macOS versions prior to 10.13, specifically within the "Directory Utility" component. A local attacker can exploit this to discover the Apple ID of the computer's owner. The CVSS score is 3.3, indicating low attack complexity and impact, with no integrity or availability compromise. There is no known exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on the KEV catalog, suggesting it is not actively exploited. Community discussion and media coverage are minimal, aligning with the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.12.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.