Junglewise Threat Intelligence

CVE-2017-0005: Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability

CVE-2017-0005 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-24

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows 8.1, Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows 7, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

The Graphics Device Interface (GDI) in Microsoft Windows contains a privilege escalation vulnerability that allows local users to gain elevated privileges via a crafted application. This vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 -
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT 8.1 -
  • Microsoft Windows 10 Gold, 1511, 1607

Timeline

  • 2017-03-14: patched: MSRC advisory published date (implied by CVE year and reference links)
  • 2017-03-27: disclosed: Technical blog post regarding detection and mitigation published.
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats