Junglewise Threat Intelligence

CVE-2017-0263: Microsoft Win32k Privilege Escalation Vulnerability

CVE-2017-0263 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-10

Technologies: Microsoft Windows Server 2008, Microsoft Windows 8.1, Microsoft Windows Rt 8.1, Microsoft Windows 10, Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Win32K, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

Microsoft Win32k kernel-mode drivers contain a use-after-free vulnerability (CWE-416) that allows local users to escalate privileges. An attacker can exploit this by running a specially crafted application to gain elevated system permissions.

Affected products

  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 Gold
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows RT 8.1 Gold
  • Microsoft Windows 10 Gold, 1511, 1607, 1703
  • Microsoft Windows Server 2016 Gold

Timeline

  • 2017-05-09: advisory: MSRC advisory published (based on BID 98258 date)
  • 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-10: disclosed: NVD publication date
  • 2022-08-10: other: CISA KEV remediation due date

Related threats