Vulnerability record · CVE-2017-17482 · published 7 February 2018
CVE-2017-17482: Hp openvms memory buffer overflow vulnerability
Hp · Openvms
An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on VAX and Alpha and may cause a process crash on IA64. Software was affected regardless of whether it was directly shipped by VMS Software, Inc. (VSI), HPE, HP, Compaq, or Digital Equipment Corporation.
Description
An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on VAX and Alpha and may cause a process crash on IA64. Software was affected regardless of whether it was directly shipped by VMS Software, Inc. (VSI), HPE, HP, Compaq, or Digital Equipment Corporation.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openvms.org/node/121 | Vendor Advisory |
| https://groups.google.com/forum/#%21topic/comp.os.vms/BYIUQ0lJ-s0 | |
| https://www.theregister.co.uk/2018/02/06/openvms_vulnerability/ | Third Party Advisory |
| http://www.openvms.org/node/121 | Vendor Advisory |
| https://groups.google.com/forum/#%21topic/comp.os.vms/BYIUQ0lJ-s0 | |
| https://www.theregister.co.uk/2018/02/06/openvms_vulnerability/ | Third Party Advisory |
Track CVE-2017-17482 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-17482), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.