{"api_version":"1","generated_at":"2026-07-23T01:50:55+00:00","cve":"CVE-2017-2385","urls":{"html":"https://cve.report/CVE-2017-2385","api":"https://cve.report/api/cve/CVE-2017-2385.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-2385","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-2385"},"summary":{"title":"CVE-2017-2385","description":"An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the \"Safari Login AutoFill\" component. It allows local users to obtain access to locked keychain items via unspecified vectors.","state":"PUBLISHED","assigner":"apple","published_at":"2017-04-02 01:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://support.apple.com/HT207600","name":"https://support.apple.com/HT207600","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of Safari 10.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1038137","name":"http://www.securitytracker.com/id/1038137","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Safari Multiple Bugs Let Remote Users Obtain Potentially Sensitive Information, Conduct Cross-Site Scripting Attacks, Bypass Security, Deny Service, and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/97136","name":"http://www.securityfocus.com/bid/97136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apple Safari CVE-2017-2385 Local Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-2385","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-2385","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"2385","vulnerable":"1","versionEndIncluding":"10.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T13:55:05.434Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1038137","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1038137"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.apple.com/HT207600"},{"name":"97136","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/97136"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-03-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the \"Safari Login AutoFill\" component. It allows local users to obtain access to locked keychain items via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-11T09:57:01.000Z","orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple"},"references":[{"name":"1038137","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1038137"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.apple.com/HT207600"},{"name":"97136","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/97136"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2017-2385","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the \"Safari Login AutoFill\" component. It allows local users to obtain access to locked keychain items via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1038137","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1038137"},{"name":"https://support.apple.com/HT207600","refsource":"CONFIRM","url":"https://support.apple.com/HT207600"},{"name":"97136","refsource":"BID","url":"http://www.securityfocus.com/bid/97136"}]}}}},"cveMetadata":{"assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","cveId":"CVE-2017-2385","datePublished":"2017-04-02T01:36:00.000Z","dateReserved":"2016-12-01T00:00:00.000Z","dateUpdated":"2024-08-05T13:55:05.434Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-04-02 01:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionEndIncluding":"10.0.3","matchCriteriaId":"825911CC-F341-4198-B830-E7CF701BB88D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"2385","Ordinal":"1","Title":"CVE-2017-2385","CVE":"CVE-2017-2385","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"2385","Ordinal":"1","NoteData":"An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the \"Safari Login AutoFill\" component. It allows local users to obtain access to locked keychain items via unspecified vectors.","Type":"Description","Title":"CVE-2017-2385"},{"CveYear":"2017","CveId":"2385","Ordinal":"2","NoteData":"2017-04-01","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"2385","Ordinal":"3","NoteData":"2017-07-11","Type":"Other","Title":"Modified"}]}}}