PT-2017-2793 · Microsoft · Windows Rt 8.1+5
Published
2017-09-12
·
Updated
2019-10-03
·
CVE-2017-8628
CVSS v2.0
7.9
High
| Vector | AV:A/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Server 2008 SP2
Windows 7 SP1
Windows 8.1
Windows RT 8.1
Windows 10 versions 1511 through 1703
Description
The issue is related to the implementation of the Bluetooth protocol in Windows operating systems, specifically concerning incorrect security requirements. This allows a remote attacker to create a network interface and potentially conduct a "man-in-the-middle" attack. The vulnerability can be exploited by attackers to affect the system.
Recommendations
For Windows Server 2008 SP2, update the system to apply the necessary security patches.
For Windows 7 SP1, apply the available security update to resolve the issue.
For Windows 8.1 and Windows RT 8.1, install the latest security patch to fix the vulnerability.
For Windows 10 versions 1511 through 1703, update to a newer version of Windows 10 that includes the security fix.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10
Windows 7 Sp1
Windows 8.1
Windows Rt 8.1
Windows Server 2008 R2