PT-2017-1532 · Microsoft · Windows Server 2016+8
Publicado
2017-03-14
·
Atualizado
2017-07-12
·
CVE-2017-0102
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Windows Vista SP2
Windows Server 2008 SP2 and R2
Windows 7 SP1
Windows 8.1
Windows Server 2012 Gold and R2
Windows RT 8.1
Windows 10 versions Gold, 1511, and 1607
Windows Server 2016
Description
The issue is caused by Windows failing to properly validate buffer lengths, allowing attackers with access to target systems to gain privileges. This can be exploited by a local attacker to elevate their privileges. The vulnerability is related to improper buffer length checking in the Windows operating system.
Recommendations
For Windows Vista SP2, apply the recommended patch to fix the issue.
For Windows Server 2008 SP2 and R2, apply the recommended patch to fix the issue.
For Windows 7 SP1, apply the recommended patch to fix the issue.
For Windows 8.1, apply the recommended patch to fix the issue.
For Windows Server 2012 Gold and R2, apply the recommended patch to fix the issue.
For Windows RT 8.1, apply the recommended patch to fix the issue.
For Windows 10 versions Gold, 1511, and 1607, apply the recommended patch to fix the issue.
For Windows Server 2016, apply the recommended patch to fix the issue.
As a temporary workaround, consider restricting access to sensitive system resources until a patch is available.
Correção
LPE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows
Windows 10
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2012
Windows Server 2016
Windows Vista