CVE-2017-8422
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.8%
from disclosure to weapon1 days
Published on NVDMay 17
1st PoC+1d
exploitation probability
1.8%top 24% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/42053/unverifiedexploitdbwww.exploit-db.com/exploits/42053unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/errata/RHSA-2017:1264https://bugzilla.redhat.com/show_bug.cgi?id=1449647https://cgit.kde.org/kauth.git/commit/?id=df875f725293af53399f5146362eb158b4f9216ahttps://cgit.kde.org/kdelibs.git/commit/?id=264e97625abe2e0334f97de17f6ffb52582888abhttps://security.gentoo.org/glsa/201706-29https://www.exploit-db.com/exploits/42053/https://www.kde.org/info/security/advisory-20170510-1.txthttp://www.debian.org/security/2017/dsa-3849http://www.openwall.com/lists/oss-security/2017/05/10/3http://www.securityfocus.com/bid/98412http://www.securitytracker.com/id/1038480