High severity7.8NVD Advisory· Published Feb 7, 2018· Updated Jun 17, 2026
CVE-2017-17482
CVE-2017-17482
Description
An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on VAX and Alpha and may cause a process crash on IA64. Software was affected regardless of whether it was directly shipped by VMS Software, Inc. (VSI), HPE, HP, Compaq, or Digital Equipment Corporation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:hp:openvms:*:*:*:*:alpha:*:*:*+ 3 more
- cpe:2.3:o:hp:openvms:*:*:*:*:alpha:*:*:*range: <=8.4-2l1
- cpe:2.3:o:hp:openvms:*:*:*:*:ia64:*:*:*range: <=8.4-2l1
- cpe:2.3:o:hp:openvms:*:*:*:*:vax:*:*:*range: >=4.0
- cpe:2.3:o:hp:openvms:*:*:*:*:vms:*:*:*range: >=4.0
Patches
Vulnerability mechanics
References
3- www.openvms.org/node/121nvdVendor Advisory
- www.theregister.co.uk/2018/02/06/openvms_vulnerability/nvdThird Party Advisory
- groups.google.com/forum/nvd
News mentions
0No linked articles in our index yet.