CVE-2017-9232 is a critical privilege escalation vulnerability affecting Canonical Juju versions prior to 1.25.12, 2.0.4, and 2.1.3. The flaw stems from Juju's improper permission settings on a UNIX domain socket, allowing local users to escalate privileges to root. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable with low attack complexity and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While not currently on the KEV catalog or Hot List, a Metasploit module exists for exploitation, indicating readily available exploit code. Despite its severity and exploit availability, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.25.12CPE matchmatch criteria | cpe:2.3:a:canonical:juju:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:canonical:juju:2.0.0:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:canonical:juju:2.0.0:alpha1:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:canonical:juju:2.0.0:alpha2:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:canonical:juju:2.0.0:beta1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.