NTFS-3G: Privilege Escalation Key Information Vulnerability Description: A vulnerability in NTFS-3G allows local users to gain root privileges. GLSA ID: 201702-10 Affected Version: Unaffected Version: Release Date: February 19, 2017 Background NTFS-3G is a stable, full-featured, read-write NTFS driver for various operating systems. Description The NTFS-3G driver does not properly clear environment variables before invoking or . Impact A local user could gain root privileges. Workaround No known workaround at this time. However, on Gentoo, if the "suid" USE flag is not set (default), an attacker cannot exploit the flaw. Resolution All NTFS-3G users should upgrade to the latest version: References CVE: CVE-2017-0358 GLSA: GLSA-201603-04, GLSA-201701-19 Severity Normal Exploitability Local