CVE-2017-0213
high · 7.3Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-03-28Remediation due 2022-04-18
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.
7.3
CVSS
84.1%
EPSS (exploit prob.)
100th
EPSS percentile
2017-05-12
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_10_1507 | all versions |
| microsoft | windows_10_1511 | all versions |
| microsoft | windows_10_1607 | all versions |
| microsoft | windows_10_1703 | all versions |
| microsoft | windows_7 | all versions |
| microsoft | windows_8.1 | all versions |
| microsoft | windows_rt_8.1 | all versions |
| microsoft | windows_server_2008 | all versions |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | all versions |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2016 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/98102
- http://www.securitytracker.com/id/1038457
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0213
- https://www.exploit-db.com/exploits/42020/
- http://www.securityfocus.com/bid/98102
- http://www.securitytracker.com/id/1038457
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0213
- https://www.exploit-db.com/exploits/42020/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0213
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-0213