CVE-2017-0104Integer Overflow or Wraparound in Corporation Isns Server

Severity
8.1HIGHNVD
EPSS
34.9%
top 2.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 14

Description

The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2, and Windows Server 2016 allows remote attackers to issue malicious requests via an integer overflow, aka "iSNS Server Memory Corruption Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Patches

🔴Vulnerability Details

1
GHSA
GHSA-3fh7-pmqp-67hr: The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2, and Windows Server 2016 allows remote attackers2022-05-14

📋Vendor Advisories

1
Microsoft
iSNS Server Memory Corruption Vulnerability2017-03-14

🕵️Threat Intelligence

1
Fortinet
iSNS Server Memory Corruption Vulnerability in Microsoft Windows Server2017-03-23