AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-15108

HIGH · CVSS 7.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-01-20 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-15108
Severity
HIGH
CVSS
7.8
EPSS
0.42%

Original NVD Description

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.