CVE-2017-0263
CVE-2017-0263
Vexday Risk Score
76High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 10.0%KEV simPoC públicaNuclei —Metasploit —Patch —
Lifecycle
12 May 2017Published on NVD
26 Mar 2018Public PoC
10 Feb 2022Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short
A flaw in Windows kernel drivers allows a local user to run malicious code with higher privileges than their account should allow. An attacker with basic access to a computer could use this to take complete control.
Technical detail
This CWE-416 (use-after-free) vulnerability in kernel-mode drivers can be exploited by a local attacker through a crafted application to trigger memory corruption, leading to privilege escalation from user mode to kernel mode. Successful exploitation requires local access and execution capability but results in full system compromise.
Summary generated and translated by AI from the official description.
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Microsoft Corporation · Microsoft Windowspublic PoCs found — 3
githubgithub.com/R06otMD5/cve-2017-0263-poc★ 0cve_referencewww.exploit-db.com/exploits/44478/unverifiedexploitdbwww.exploit-db.com/exploits/44478unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0263https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0263https://www.exploit-db.com/exploits/44478/https://xiaodaozhi.com/exploit/117.htmlhttp://www.securityfocus.com/bid/98258http://www.securitytracker.com/id/1038449