Skip to content
COOEY

EXPOSURES › CVE-2017-1000253

CVE-2017-1000253

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-1000253 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

A local attacker can escalate privileges via a PIE stack buffer corruption vulnerability in the Linux kernel's load_elf_ binary() function.

This kernel vulnerability allows local privilege escalation, which is a critical failure for any DIB organization relying on Linux systems. The fact that it is in the KEV catalog and linked to ransomware means it was actively exploited in the wild, indicating a severe lapse in patching and threat monitoring. DIBs must ensure their Linux kernel is patched to the latest version and monitor KEV for actively exploited vulnerabilities.

Shame score — A critical, actively exploited kernel vulnerability linked to ransomware that was left unpatched long enough to be cataloged in KEV.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.