PT-2017-3103 · Microsoft · Windows Server 2016+2

Richard Shupak

·

Published

2017-10-10

·

Updated

2019-10-03

·

CVE-2017-11769

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions 10 Gold, 1511, 1607, and 1703 Microsoft Windows Server 2016
Description The issue is related to errors that occur when loading DLL files, allowing a remote attacker to execute arbitrary code using specially crafted DLL files. This can be achieved through the exploitation of the TRIE component in the Windows operating system. The estimated number of potentially affected devices and details about real-world incidents where this issue was exploited are not specified.
Recommendations For Microsoft Windows versions 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, update to a version that includes the fix for the TRIE component issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02486
CVE-2017-11769

Affected Products

Windows
Windows 10
Windows Server 2016