CVE-2017-11779
high · 8.1The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability".
8.1
CVSS
33.3%
EPSS (exploit prob.)
98th
EPSS percentile
2017-10-13
Published
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_10 | all versions |
| microsoft | windows_10 | 1511 |
| microsoft | windows_10 | 1607 |
| microsoft | windows_10 | 1703 |
| microsoft | windows_8.1 | all versions |
| microsoft | windows_rt_8.1 | all versions |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2016 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/101166
- http://www.securitytracker.com/id/1039533
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11779
- http://www.securityfocus.com/bid/101166
- http://www.securitytracker.com/id/1039533
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11779
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-11779