CVE-2017-7622

UnknownEPSS 1.27%

Last modified

CVE-2017-7622 is a vulnerability of currently unknown severity. dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus. Anybody can change the grub config, even to append some arguments to make a backdoor or privilege escalation, by calling DoWriteGrubSettings() provided by dde-daemon.. EPSS estimates a 1.27% chance of exploitation in the next 30 days.

Description

dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus. Anybody can change the grub config, even to append some arguments to make a backdoor or privilege escalation, by calling DoWriteGrubSettings() provided by dde-daemon.

Metrics

EPSS Probability
1.27%

66.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DeepinDeepin Desktop Environment15.0
DeepinDeepin Desktop Environment15.1
DeepinDeepin Desktop Environment15.2
DeepinDeepin Desktop Environment15.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-7622?
dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus. Anybody can change the grub config, even to append some arguments to make a backdoor or privilege escalation, by calling DoWriteGrubSettings() provided by dde-daemon.
How severe is CVE-2017-7622?
Severity scoring for CVE-2017-7622 is pending analysis. The EPSS model estimates a 1.27% probability of exploitation in the next 30 days.
How do I fix CVE-2017-7622?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-7622?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST