CVE-2017-0158Out-of-bounds Write in Corporation Windows

12 documents9 sources
Severity
7.5HIGHNVD
EPSS
19.8%
top 4.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateMay 13

Description

An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages17 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-37x9-fvf9-4wq8: An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 82022-05-13

📋Vendor Advisories

1
Microsoft
Scripting Engine Memory Corruption Vulnerability2017-04-11

🕵️Threat Intelligence

6
Fortinet
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations2017-09-05
Talos
When combining exploits for added effect goes wrong2017-08-14
Talos
Microsoft Patch Tuesday - April 20172017-04-12
Talos
Microsoft Patch Tuesday - April 20172017-04-12
Recorded Future
China's Influence on National Network Vulnerability Publications | Recorded Future
CVE-2017-0158 — Out-of-bounds Write | cvebase