CVE-2017-7523
 
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.
Cygwin versiones 1.7.2 hasta e incluyendo a 1.8.0, son susceptibles a una vulnerabilidad de desbordamiento de búfer en las funciones wcsxfrm y wcsxfrm_l resultando en una denegación de servicio por el bloqueo o el posible secuestro del proceso que se ejecuta con privilegios administrativos activado por una cadena de entrada especialmente creada.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-04-05 CVE Reserved
- 2017-07-21 CVE Published
- 2023-05-31 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://cygwin.com/ml/cygwin/2017-05/msg00149.html | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.2 Search vendor "Cygwin" for product "Cygwin" and version "1.7.2" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.3 Search vendor "Cygwin" for product "Cygwin" and version "1.7.3" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.5 Search vendor "Cygwin" for product "Cygwin" and version "1.7.5" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.6 Search vendor "Cygwin" for product "Cygwin" and version "1.7.6" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.7 Search vendor "Cygwin" for product "Cygwin" and version "1.7.7" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.8 Search vendor "Cygwin" for product "Cygwin" and version "1.7.8" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.9 Search vendor "Cygwin" for product "Cygwin" and version "1.7.9" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.10 Search vendor "Cygwin" for product "Cygwin" and version "1.7.10" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.11 Search vendor "Cygwin" for product "Cygwin" and version "1.7.11" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.12 Search vendor "Cygwin" for product "Cygwin" and version "1.7.12" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.13 Search vendor "Cygwin" for product "Cygwin" and version "1.7.13" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.14 Search vendor "Cygwin" for product "Cygwin" and version "1.7.14" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.15 Search vendor "Cygwin" for product "Cygwin" and version "1.7.15" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.16 Search vendor "Cygwin" for product "Cygwin" and version "1.7.16" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.17 Search vendor "Cygwin" for product "Cygwin" and version "1.7.17" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.18 Search vendor "Cygwin" for product "Cygwin" and version "1.7.18" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.19 Search vendor "Cygwin" for product "Cygwin" and version "1.7.19" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.21 Search vendor "Cygwin" for product "Cygwin" and version "1.7.21" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.22 Search vendor "Cygwin" for product "Cygwin" and version "1.7.22" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.23 Search vendor "Cygwin" for product "Cygwin" and version "1.7.23" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.24 Search vendor "Cygwin" for product "Cygwin" and version "1.7.24" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.25 Search vendor "Cygwin" for product "Cygwin" and version "1.7.25" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.26 Search vendor "Cygwin" for product "Cygwin" and version "1.7.26" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.27 Search vendor "Cygwin" for product "Cygwin" and version "1.7.27" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.28 Search vendor "Cygwin" for product "Cygwin" and version "1.7.28" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.29 Search vendor "Cygwin" for product "Cygwin" and version "1.7.29" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.31 Search vendor "Cygwin" for product "Cygwin" and version "1.7.31" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.32 Search vendor "Cygwin" for product "Cygwin" and version "1.7.32" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.33 Search vendor "Cygwin" for product "Cygwin" and version "1.7.33" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.34 Search vendor "Cygwin" for product "Cygwin" and version "1.7.34" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.7.35 Search vendor "Cygwin" for product "Cygwin" and version "1.7.35" | - |
Affected
| ||||||
Cygwin Search vendor "Cygwin" | Cygwin Search vendor "Cygwin" for product "Cygwin" | 1.8.0 Search vendor "Cygwin" for product "Cygwin" and version "1.8.0" | - |
Affected
|