← back
CVE-2017-0263highunder attackCWE-416

CVE-2017-0263

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA, has a public proof of concept and 1 threat group(s) use it.

ssvc Actcvss 7.8epss 10%
from disclosure to weapon318 days
Published on NVDMay 12
1st PoC+318d
CISA KEV+1735d
exploitation probability
10%top 5% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 group(s)3 public exploit(s)
Who exploits it1

Groups known to exploit this vulnerability (MITRE ATT&CK attribution).

Action required by CISAfederal deadline: 2022-08-10

Apply updates per vendor instructions.

In short

A flaw in Windows kernel drivers allows a local user to run malicious code with higher privileges than their account should allow. An attacker with basic access to a computer could use this to take complete control.

Technical detail

This CWE-416 (use-after-free) vulnerability in kernel-mode drivers can be exploited by a local attacker through a crafted application to trigger memory corruption, leading to privilege escalation from user mode to kernel mode. Successful exploitation requires local access and execution capability but results in full system compromise.

Summary generated and translated by AI from the official description.
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.