CVE-2017-0358
HIGHDebian/Ubuntu ntfs-3g Local Privilege Escalation
Title source: metasploitDescription
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Google Security Research · textlocallinux
https://www.exploit-db.com/exploits/41356
exploitdb
WORKING POC
by Kristian Erik Hermansen · bashlocallinux
https://www.exploit-db.com/exploits/41240
metasploit
WORKING POC
GOOD
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/ntfs3g_priv_esc.rb
References (7)
Scores
CVSS v3
7.8
EPSS
0.0755
EPSS Percentile
91.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-269
Status
published
Products (2)
debian/debian_linux
8.0
tuxera/ntfs-3g
< 2016.2.22
Published
Apr 13, 2018
Tracked Since
Feb 18, 2026