ntfs-3g: Modprobe influence vulnerability via environment variables
Published Apr 13, 2018
7.8
HIGHCVSS 3.1
EPSS 2.19%
Description
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
Affected products
Configuration 2
- 8.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Dec 4, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.19% (0.02189) | 81.77th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.28% (0.02277) | 80.77th | v5 (v2026.06.15) |
| Nov 29, 2025 | 7.55% (0.07546) | 91.45th | v4 (v2025.03.14) |
| Nov 8, 2025 | 17.45% (0.17454) | 94.78th | v4 (v2025.03.14) |
| Oct 11, 2025 | 15.92% (0.15924) | 94.43th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.45% (0.10449) | 92.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 15.29% (0.15294) | 91.07th | v4 (v2025.03.14) |
| Mar 28, 2025 | 10.45% (0.10449) | 92.53th | v4 (v2025.03.14) |
| Mar 27, 2025 | 15.29% (0.15294) | 93.70th | v4 (v2025.03.14) |
| Mar 20, 2025 | 14.27% (0.14266) | 93.88th | v4 (v2025.03.14) |
| Mar 19, 2025 | 15.29% (0.15294) | 93.82th | v4 (v2025.03.14) |
| Mar 17, 2025 | 14.27% (0.14266) | 93.87th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.13% (0.00126) | 48.88th | v3 (v2023.03.01) |
| Jul 10, 2024 | 0.13% (0.00126) | 47.70th | v3 (v2023.03.01) |
| Apr 7, 2023 | 0.13% (0.00126) | 45.69th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.12% (0.00116) | 43.71th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.32% (0.02320) | 81.41th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.32% (0.02320) | 79.65th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.32% (0.02320) | 58.29th | v2 (v2022.01.01) |
| Feb 3, 2022 | 22.90% (0.22897) | 94.83th | v1 |
| Jan 6, 2022 | 22.90% (0.22897) | 94.77th | v1 |
| Sep 16, 2021 | 22.90% (0.22897) | 98.00th | v1 |
| Sep 14, 2021 | 3.86% (0.03864) | 83.15th | v1 |
| Sep 1, 2021 | 22.90% (0.22897) | 98.04th | v1 |
| Apr 14, 2021 | 22.90% (0.22897) | 0.00th | v1 |
References (7)
- http://www.openwall.com/lists/oss-security/2017/02/04/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/95987 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://marc.info/?l=oss-security&m=148594671929354&w=2 mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201702-10 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.debian.org/security/2017/dsa-3780 vendor-advisoryx_refsource_DEBIAN
- https://www.exploit-db.com/exploits/41240/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41356/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2017/02/04/1 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| http://www.securityfocus.com/bid/95987 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://marc.info/?l=oss-security&m=148594671929354&w=2 | mailing-listx_refsource_MLISTExploitMailing ListThird Party Advisory | |
| https://security.gentoo.org/glsa/201702-10 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.debian.org/security/2017/dsa-3780 | vendor-advisoryx_refsource_DEBIAN | |
| https://www.exploit-db.com/exploits/41240/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry | |
| https://www.exploit-db.com/exploits/41356/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.