{"api_version":"1","generated_at":"2026-07-23T07:34:32+00:00","cve":"CVE-2017-1233","urls":{"html":"https://cve.report/CVE-2017-1233","api":"https://cve.report/api/cve/CVE-2017-1233.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-1233","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-1233"},"summary":{"title":"CVE-2017-1233","description":"IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2018-01-31 15:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-863"],"metrics":[],"references":[{"url":"http://www.ibm.com/support/docview.wss?uid=swg22011765","name":"http://www.ibm.com/support/docview.wss?uid=swg22011765","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123912","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123912","refsource":"MISC","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-1233","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1233","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"1233","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"bigfix_remote_control","cpe6":"9.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"1233","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"bigfix_remote_control","cpe6":"9.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2017-12-20T00:00:00","ID":"CVE-2017-1233","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"BigFix Remote Control","version":{"version_data":[{"version_value":"9.1.4"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Gain Privileges"}]}]},"references":{"reference_data":[{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123912","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/123912"},{"name":"http://www.ibm.com/support/docview.wss?uid=swg22011765","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=swg22011765"}]}},"nvd":{"publishedDate":"2018-01-31 15:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-863"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:bigfix_remote_control:9.1.4:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"1233","Ordinal":"97306","Title":"CVE-2017-1233","CVE":"CVE-2017-1233","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"1233","Ordinal":"1","NoteData":"IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"1233","Ordinal":"2","NoteData":"2018-01-31","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"1233","Ordinal":"3","NoteData":"2018-01-31","Type":"Other","Title":"Modified"}]}}}