PT-2017-2411 · Microsoft · Windows Server 2003+2
Published
2017-06-15
·
Updated
2019-10-03
·
CVE-2017-8487
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows versions prior to the fixed version
Windows XP
Windows Server 2003
Description
The issue is related to insufficient access control in the Windows OLE component, allowing an attacker to execute arbitrary code when a victim opens a specially crafted file or program.
Recommendations
For Windows XP, consider applying security patches or updates to fix the issue.
For Windows Server 2003, apply the relevant security update to resolve the vulnerability.
As a temporary workaround, consider restricting access to potentially vulnerable files or programs until a patch is available.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Ole
Windows Server 2003
Windows Xp