9.3

CVE-2017-0166

An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version 1511
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 10 Version 1703
Microsoft ≫ Windows 7 Version - Update sp1 Edition x64
Microsoft ≫ Windows 7 Version - Update sp1 Edition x86
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Windows Vista Version - Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.42% 0.928
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-131 Incorrect Calculation of Buffer Size

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

http://www.securityfocus.com/bid/97446
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038245
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0166
Patch
Vendor Advisory
Mitigation