PT-2017-3103 · Microsoft · Windows Server 2016+2
Richard Shupak
·
Published
2017-10-10
·
Updated
2019-10-03
·
CVE-2017-11769
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 10 Gold, 1511, 1607, and 1703
Microsoft Windows Server 2016
Description
The issue is related to errors that occur when loading DLL files, allowing a remote attacker to execute arbitrary code using specially crafted DLL files. This can be achieved through the exploitation of the TRIE component in the Windows operating system. The estimated number of potentially affected devices and details about real-world incidents where this issue was exploited are not specified.
Recommendations
For Microsoft Windows versions 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, update to a version that includes the fix for the TRIE component issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10
Windows Server 2016