peter bassill · operator
$ cve CVE-2018-12327 JSON

CVE-2018-12327 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 28% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq or ntpdc is used with a command line from an untrusted source.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS28.02% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploityes
Published2018-06-20
Last modified2026-06-17

Affected (1)

VendorProduct
ntpntp

Public exploits

SourceTitleDate
exploit-dbntp 4.2.8p11 - Local Buffer Overflow (PoC)2018-06-20

References

→ the Explorer  ·  watch your stack  ·  NVD