CVE-2017-0263
CVE-2017-0263
In short
A flaw in Windows kernel drivers allows a local user to run malicious code with higher privileges than their account should allow. An attacker with basic access to a computer could use this to take complete control.
Technical detail
This CWE-416 (use-after-free) vulnerability in kernel-mode drivers can be exploited by a local attacker through a crafted application to trigger memory corruption, leading to privilege escalation from user mode to kernel mode. Successful exploitation requires local access and execution capability but results in full system compromise.
Summary generated and translated by AI from the official description.
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Microsoft Corporation · Microsoft Windowspublic PoCs found — 3
githubgithub.com/R06otMD5/cve-2017-0263-poc★ 0cve_referencewww.exploit-db.com/exploits/44478/unverifiedexploitdbwww.exploit-db.com/exploits/44478unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0263https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0263https://www.exploit-db.com/exploits/44478/https://xiaodaozhi.com/exploit/117.htmlhttp://www.securityfocus.com/bid/98258http://www.securitytracker.com/id/1038449