VulnerabilityModified
CVE-2017-6553
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.
CRITICAL 9.8EPSS 42.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 42.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 42.29% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- quest/privilege manager for unix
- Source
- cve@mitre.org
References
- https://0xdeadface.wordpress.com/2017/04/07/multiple-vulnerabilities-in-quest-privilege-manager-6-0-0-xx-cve-2017-6553-cve-2017-6554/Third Party Advisory
- https://support.oneidentity.com/privilege-manager-for-unix/kb/SOL133824Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/42010/
- https://0xdeadface.wordpress.com/2017/04/07/multiple-vulnerabilities-in-quest-privilege-manager-6-0-0-xx-cve-2017-6553-cve-2017-6554/Third Party Advisory
- https://support.oneidentity.com/privilege-manager-for-unix/kb/SOL133824Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/42010/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.