PT-2017-1532 · Microsoft · Windows Server 2016+8

Published

2017-03-14

·

Updated

2017-07-12

·

CVE-2017-0102

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to the fixed version Windows Vista SP2 Windows Server 2008 SP2 and R2 Windows 7 SP1 Windows 8.1 Windows Server 2012 Gold and R2 Windows RT 8.1 Windows 10 versions Gold, 1511, and 1607 Windows Server 2016
Description The issue is caused by Windows failing to properly validate buffer lengths, allowing attackers with access to target systems to gain privileges. This can be exploited by a local attacker to elevate their privileges. The vulnerability is related to improper buffer length checking in the Windows operating system.
Recommendations For Windows Vista SP2, apply the recommended patch to fix the issue. For Windows Server 2008 SP2 and R2, apply the recommended patch to fix the issue. For Windows 7 SP1, apply the recommended patch to fix the issue. For Windows 8.1, apply the recommended patch to fix the issue. For Windows Server 2012 Gold and R2, apply the recommended patch to fix the issue. For Windows RT 8.1, apply the recommended patch to fix the issue. For Windows 10 versions Gold, 1511, and 1607, apply the recommended patch to fix the issue. For Windows Server 2016, apply the recommended patch to fix the issue. As a temporary workaround, consider restricting access to sensitive system resources until a patch is available.

Fix

LPE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00677
CVE-2017-0102

Affected Products

Windows
Windows 10
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2012
Windows Server 2016
Windows Vista