CVE-2017-7884

HIGH

In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by r...

Affects 1 product across 1 vendor.

BCS5.31
CVSS 3.08.4
EPSS0.4%
Percentile35th
PatchUnknown
CVSS Vector — Plain English Requires local access, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-427: CWE-427
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2017. A high severity vulnerability affects Apcupsd systems (CVE-2017-7884). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2017-GLOBAL-267347-H • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2017-7884?
This vulnerability was disclosed in 2017. A high severity vulnerability affects Apcupsd systems (CVE-2017-7884). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2017-7884?
CVE-2017-7884 has CVSS 8.4 (High). Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2017-7884 actively exploited?
No confirmed active exploitation of CVE-2017-7884 as of 2026-05-30.
How do I remediate CVE-2017-7884?
Priority: MEDIUM.
What systems are affected by CVE-2017-7884?
CVE-2017-7884 affects: Apcupsd.
Vulnerability Details
CVE IDCVE-2017-7884
BSIDBS-2017-GLOBAL-267347-H BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2017-06-16
Last Modified2026-05-13
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup. This occurs because of "RW NT AUTHORITY\Authenticated Users" permissions for %SYSTEMDRIVE%\apcupsd\bin\apcupsd.exe.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup. This occurs because of "RW NT AUTHORITY\Authenticated Users" permissions for %SYSTEMDRIVE%\apcupsd\bin\apcupsd.exe. CVSS vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Apcupsd Apc Ups Daemon
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3313 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash650d7f4b04bbb979e194411e28d5e08a908ff9e26fc551861d600b498cf269f0b3d161758f5cb7b6c66b919b530ce6a8660956bd26932239fa5a92f99484ff5d
Related CVEs affecting Apcupsd
CVE-2003-0098 10.0 Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allo... CVE-2019-12585 9.8 Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other produ... CVE-2019-12584 6.1 Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other produ...
View all Apcupsd CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →