CVE-2017-0158
high · 7.5An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."
7.5
CVSS
12.8%
EPSS (exploit prob.)
96th
EPSS percentile
2017-04-12
Published
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_10 | all versions |
| microsoft | windows_10 | 1511 |
| microsoft | windows_10 | 1607 |
| microsoft | windows_10 | 1703 |
| microsoft | windows_7 | all versions |
| microsoft | windows_8.1 | all versions |
| microsoft | windows_rt_8.1 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | all versions |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2016 | all versions |
| microsoft | windows_vista | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/97455
- http://www.securitytracker.com/id/1038238
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0158
- http://www.securityfocus.com/bid/97455
- http://www.securitytracker.com/id/1038238
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0158
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-0158