Vulnerability record · CVE-2017-9232 · published 28 May 2017
CVE-2017-9232: Juju UNIX domain socket permissions allow local privilege escalation to root
Canonical · Juju
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 creates a UNIX domain socket without appropriate permissions. Because the socket is not properly restricted, any local user on the system can interact with it and escalate privileges to root.
Description
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to root with public exploit code and very high EPSS, though it requires an existing local foothold and is not in KEV.
What it is
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 creates a UNIX domain socket without appropriate permissions. Because the socket is not properly restricted, any local user on the system can interact with it and escalate privileges to root.
Impact
A local unprivileged user gains root-level control of the host running Juju, allowing full compromise of the machine and any workloads or credentials it manages.
Attack surface
The flaw is reached through a local UNIX domain socket on the Juju host; no network access is required, and no authentication or user interaction beyond local access to the system is needed.
Exploitation
No CISA KEV listing, but EPSS is 0.485 (98.8th percentile) and references include an Exploit-tagged Launchpad bug and an Exploit-DB entry, indicating public exploit code exists.
What to do
- Upgrade Juju to 1.25.12, 2.0.4, 2.1.3 or later as applicable to your release line.
- Restrict filesystem permissions on the Juju UNIX domain socket so only the Juju service account can access it.
- Limit interactive shell access on hosts running Juju to trusted administrators only.
- Audit Juju-managed hosts for unexpected local accounts or privilege changes after exposure.
Detection
- Monitor for local processes connecting to the Juju UNIX domain socket outside the expected Juju service account.
- Alert on unexpected root-level process creation or privilege changes on Juju hosts.
- Review file permission changes on the Juju socket path and related directories.
- Correlate local authentication and sudo/su activity with Juju socket access on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/98737 | Third Party AdvisoryVDB Entry |
| https://bugs.launchpad.net/juju/+bug/1682411 | ExploitIssue TrackingThird Party Advisory |
| https://www.exploit-db.com/exploits/44023/ | |
| http://www.securityfocus.com/bid/98737 | Third Party AdvisoryVDB Entry |
| https://bugs.launchpad.net/juju/+bug/1682411 | ExploitIssue TrackingThird Party Advisory |
| https://www.exploit-db.com/exploits/44023/ |
Track CVE-2017-9232 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9232), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.