CVE-2017-0164Improper Input Validation in Corporation Active Directory

Severity
4.4MEDIUMNVD
EPSS
5.4%
top 9.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateMay 17

Description

A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.7 | Impact: 3.6

Patches

🔴Vulnerability Details

1
GHSA
GHSA-v9mj-gv7c-j2c8: A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious se2022-05-17

📋Vendor Advisories

1
Microsoft
Active Directory Denial of Service Vulnerability2017-04-11

🕵️Threat Intelligence

2
Recorded Future
China's Influence on National Network Vulnerability Publications | Recorded Future
Recorded Future
China's Influence on National Network Vulnerability Publications