VulnerabilityModified
CVE-2017-6459
The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argument with multiple null bytes.
MEDIUM 5.5EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argument with multiple null bytes.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- ntp/ntp
- Source
- cve@mitre.org
References
- http://support.ntp.org/bin/view/Main/NtpBug3382Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_SecuVendor Advisory
- http://www.securityfocus.com/bid/97076Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038123Third Party Advisory, VDB Entry
- https://support.apple.com/HT208144
- http://support.ntp.org/bin/view/Main/NtpBug3382Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_SecuVendor Advisory
- http://www.securityfocus.com/bid/97076Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038123Third Party Advisory, VDB Entry
- https://support.apple.com/HT208144
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.