7.3

CVE-2017-0213

Warnung
Exploit
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1507 Version -
Microsoft ≫ Windows 10 1511 Version -
Microsoft ≫ Windows 10 1607 Version -
Microsoft ≫ Windows 10 1703 Version -
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64

28.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows Privilege Escalation Vulnerability

Schwachstelle

Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 84.14% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
NIST 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:N/I:P/A:N
CISA-ADP 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/98102
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1038457
Third Party Advisory
Broken Link
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0213
Patch
Vendor Advisory
https://www.exploit-db.com/exploits/42020/
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0213
US Government Resource