CVE-2017-15400
Status: ModifiedHigh (7.8)—
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.86%
- Percentile among all scored CVEs: 57
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-93
References
- https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html
- https://crbug.com/777215
- https://security.gentoo.org/glsa/201908-08
- https://www.debian.org/security/2018/dsa-4243
- https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html
- https://crbug.com/777215
- https://security.gentoo.org/glsa/201908-08
- https://www.debian.org/security/2018/dsa-4243
Raw JSON (NVD)
Show
{
"id": "CVE-2017-15400",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "chrome-cve-admin@google.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Google Chrome OS prior to 62.0.3202.74",
"versions": [
{
"status": "affected",
"version": "Google Chrome OS prior to 62.0.3202.74"
}
]
}
]
}
],
"published": "2018-02-07T23:29:00.937",
"references": [
{
"url": "https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://crbug.com/777215",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://security.gentoo.org/glsa/201908-08",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://www.debian.org/security/2018/dsa-4243",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://crbug.com/777215",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201908-08",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.debian.org/security/2018/dsa-4243",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-93"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue."
},
{
"lang": "es",
"value": "La restricción insuficiente de filtros IPP en CUPS en Google Chrome OS, en versiones anteriores a la 62.0.3202.74, permite que un atacante remoto ejecute un comando con los mismos privilegios que el demonio cups mediante un archivo PPD manipulado. Esto también se conoce como problema CRLF zeroconfig de impresora."
}
],
"lastModified": "2026-06-17T01:07:45.947",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87004649-1263-4704-A4EE-B3132BFC08FD",
"versionEndExcluding": "62.0.3202.74"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "chrome-cve-admin@google.com"
}