PT-2017-2011 · Microsoft · Windows 10 1511+5
Publicado
2017-04-11
·
Atualizado
2019-10-03
·
CVE-2017-0165
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Windows 10
Windows 10 1511
Windows 8.1
Windows RT 8.1
Windows Server 2012 R2
Description
The issue is related to insufficient access control in the operating system, which can be exploited by a local attacker to elevate their privileges. This is due to the system's failure to properly sanitize handles in memory. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations
For Windows 10, update to a version that includes the fix for this issue.
For Windows 10 1511, apply the necessary patch or update to resolve the issue.
For Windows 8.1, restrict access to sensitive system resources until a patch is available.
For Windows RT 8.1, consider disabling unnecessary features that may be exploited to elevate privileges.
For Windows Server 2012 R2, apply configuration changes to minimize the risk of exploitation, such as limiting local access to sensitive areas of the system.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows
Windows 10
Windows 10 1511
Windows 8.1
Windows Rt 8.1
Windows Server 2012 R2