ID

VAR-201712-1099


CVE

CVE-2017-7155


TITLE

Apple macOS of Intel Graphics Driver Component vulnerable to arbitrary code execution in privileged context

Trust: 0.8

sources: JVNDB: JVNDB-2017-011437

DESCRIPTION

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. Apple macOS High Sierra is a dedicated operating system developed by Apple for Mac computers

Trust: 1.71

sources: NVD: CVE-2017-7155 // JVNDB: JVNDB-2017-011437 // VULHUB: VHN-115358

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:ltversion:10.13.2

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.13.1

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.0.4

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.1

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.0.0

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.1.0

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.0.1

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion: -

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.1.1

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.0

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.0.3

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.0.2

Trust: 0.6

sources: JVNDB: JVNDB-2017-011437 // CNNVD: CNNVD-201703-894 // NVD: CVE-2017-7155

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-7155
value: HIGH

Trust: 1.0

NVD: CVE-2017-7155
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201703-894
value: CRITICAL

Trust: 0.6

VULHUB: VHN-115358
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-7155
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-115358
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-7155
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-115358 // JVNDB: JVNDB-2017-011437 // CNNVD: CNNVD-201703-894 // NVD: CVE-2017-7155

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-115358 // JVNDB: JVNDB-2017-011437 // NVD: CVE-2017-7155

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201703-894

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201703-894

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-011437

PATCH

title:Apple security updatesurl:https://support.apple.com/en-us/HT201222

Trust: 0.8

title:HT208331url:https://support.apple.com/en-us/HT208331

Trust: 0.8

title:HT208331url:https://support.apple.com/ja-jp/HT208331

Trust: 0.8

sources: JVNDB: JVNDB-2017-011437

EXTERNAL IDS

db:NVDid:CVE-2017-7155

Trust: 2.5

db:JVNid:JVNVU98418454

Trust: 0.8

db:JVNDBid:JVNDB-2017-011437

Trust: 0.8

db:CNNVDid:CNNVD-201703-894

Trust: 0.7

db:VULHUBid:VHN-115358

Trust: 0.1

sources: VULHUB: VHN-115358 // JVNDB: JVNDB-2017-011437 // CNNVD: CNNVD-201703-894 // NVD: CVE-2017-7155

REFERENCES

url:https://support.apple.com/ht208331

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-7155

Trust: 0.8

url:http://jvn.jp/vu/jvnvu98418454/index.html

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-7155

Trust: 0.8

sources: VULHUB: VHN-115358 // JVNDB: JVNDB-2017-011437 // CNNVD: CNNVD-201703-894 // NVD: CVE-2017-7155

SOURCES

db:VULHUBid:VHN-115358
db:JVNDBid:JVNDB-2017-011437
db:CNNVDid:CNNVD-201703-894
db:NVDid:CVE-2017-7155

LAST UPDATE DATE

2025-04-20T20:03:09.718000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-115358date:2017-12-29T00:00:00
db:JVNDBid:JVNDB-2017-011437date:2018-01-16T00:00:00
db:CNNVDid:CNNVD-201703-894date:2017-12-28T00:00:00
db:NVDid:CVE-2017-7155date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-115358date:2017-12-27T00:00:00
db:JVNDBid:JVNDB-2017-011437date:2018-01-16T00:00:00
db:CNNVDid:CNNVD-201703-894date:2017-03-21T00:00:00
db:NVDid:CVE-2017-7155date:2017-12-27T17:08:24.233