LiveActive security incident?Get immediate response
CVE Record

CVE-2017-8921: In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write acces...

In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this issue and CVE-2016-9956 are directory traversal vulnerabilities in Autopilot/route_mgr.cxx - this one exists because of an incomplete fix for CVE-2016-9956.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

FlightGear versions before 2017.2.1 could let untrusted FlightGear content overwrite files the current user can write. The overwrite is limited to FlightGear flightplan XML content, not arbitrary attacker data, but it could still corrupt user files or disrupt simulator workstations.

Executive priority

Treat this as a workstation integrity risk, not an enterprise-wide remote compromise based on the provided evidence. Prioritize upgrades where FlightGear is still used with third-party content or in operational training environments.

Technical view

The issue is a directory traversal flaw in FlightGear Autopilot/route_mgr.cxx exposed through the FGCommand interface. It resulted from an incomplete fix for CVE-2016-9956. A malicious third-party aircraft is cited as a possible trigger, with writes constrained to flightplan XML content.

Likely exposure

Exposure is most likely on endpoints running FlightGear before 2017.2.1, especially where users install third-party aircraft or other untrusted simulator content. The provided sources do not identify server-side exposure or broader affected products.

Exploitation context

The bundle does not show known active exploitation, and CISA KEV status is false. Public evidence describes a malicious third-party aircraft as a plausible abuse path, but does not provide exploit prevalence, observed attacks, or a CVSS score.

Researcher notes

The available record is narrow: no CVSS, CWE, CPE, or exploit-status detail is provided. Analysis should focus on the FGCommand path, route_mgr.cxx directory traversal, and whether the 2017.2.1-era fix fully blocks traversal-based file overwrite.

Mitigation direction

  • Upgrade FlightGear to 2017.2.1 or later where feasible.
  • Review the referenced FlightGear fix and vendor guidance.
  • Restrict installation of untrusted third-party aircraft or simulator content.
  • Run FlightGear with least-privileged user accounts where practical.
  • Back up user files on simulator workstations.

Validation and detection

  • Inventory FlightGear installations and confirm their versions.
  • Flag any FlightGear version earlier than 2017.2.1.
  • Review whether users install third-party aircraft or add-ons.
  • Check affected workstations for unexpected file corruption reports.
  • Document compensating controls for systems that cannot upgrade.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

File access behavior lookup

The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2017-8921 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.