PT-2017-3103 · Microsoft · Windows Server 2016+2

Richard Shupak

·

Publicado

2017-10-10

·

Atualizado

2019-10-03

·

CVE-2017-11769

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 10 Gold, 1511, 1607, and 1703 Microsoft Windows Server 2016
Description The issue is related to errors that occur when loading DLL files, allowing a remote attacker to execute arbitrary code using specially crafted DLL files. This can be achieved through the exploitation of the TRIE component in the Windows operating system. The estimated number of potentially affected devices and details about real-world incidents where this issue was exploited are not specified.
Recommendations For Microsoft Windows versions 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, update to a version that includes the fix for the TRIE component issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02486
CVE-2017-11769

Produtos afetados

Windows
Windows 10
Windows Server 2016