{"api_version":"1","generated_at":"2026-07-23T08:55:48+00:00","cve":"CVE-2017-8900","urls":{"html":"https://cve.report/CVE-2017-8900","api":"https://cve.report/api/cve/CVE-2017-8900.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-8900","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-8900"},"summary":{"title":"CVE-2017-8900","description":"LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-05-12 07:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"MEDIUM","vector":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.ubuntu.com/usn/usn-3285-1/","name":"https://www.ubuntu.com/usn/usn-3285-1/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"USN-3285-1: LightDM vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/98554","name":"http://www.securityfocus.com/bid/98554","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"LightDM CVE-2017-8900 Local Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.html","name":"https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"CVE-2017-8900 in Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://launchpad.net/bugs/1663157","name":"https://launchpad.net/bugs/1663157","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Vendor Advisory"],"title":"Bug #1663157 “Guest session processes are not confined in 16.10 ...” : Bugs : lightdm package : Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-8900","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-8900","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"8900","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"16.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"8900","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"17.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"8900","vulnerable":"1","versionEndIncluding":"1.22.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lightdm_project","cpe5":"lightdm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T16:48:22.897Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"98554","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/98554"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.ubuntu.com/usn/usn-3285-1/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://launchpad.net/bugs/1663157"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-05-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-05-24T09:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"98554","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/98554"},{"tags":["x_refsource_CONFIRM"],"url":"https://www.ubuntu.com/usn/usn-3285-1/"},{"tags":["x_refsource_CONFIRM"],"url":"https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://launchpad.net/bugs/1663157"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-8900","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"98554","refsource":"BID","url":"http://www.securityfocus.com/bid/98554"},{"name":"https://www.ubuntu.com/usn/usn-3285-1/","refsource":"CONFIRM","url":"https://www.ubuntu.com/usn/usn-3285-1/"},{"name":"https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.html","refsource":"CONFIRM","url":"https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.html"},{"name":"https://launchpad.net/bugs/1663157","refsource":"CONFIRM","url":"https://launchpad.net/bugs/1663157"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-8900","datePublished":"2017-05-12T06:54:00.000Z","dateReserved":"2017-05-11T00:00:00.000Z","dateUpdated":"2024-08-05T16:48:22.897Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-05-12 07:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:lightdm_project:lightdm:*:*:*:*:*:*:*:*","versionEndIncluding":"1.22.0","matchCriteriaId":"7CAC5354-FCCB-416A-A00F-7C337EF9099F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:16.10:*:*:*:*:*:*:*","matchCriteriaId":"1AFB20FA-CB00-4729-AB3A-816454C6D096"},{"vulnerable":false,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*","matchCriteriaId":"588D4F37-0A56-47A4-B710-4D5F3D214FB9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"8900","Ordinal":"1","Title":"CVE-2017-8900","CVE":"CVE-2017-8900","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"8900","Ordinal":"1","NoteData":"LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.","Type":"Description","Title":"CVE-2017-8900"},{"CveYear":"2017","CveId":"8900","Ordinal":"2","NoteData":"2017-05-12","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"8900","Ordinal":"3","NoteData":"2017-05-24","Type":"Other","Title":"Modified"}]}}}