CVE-2017-0173Resource Exposure in Corporation Microsoft Windows

CWE-668Resource Exposure12 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
0.6%
top 31.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 13

Description

Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This CVE ID is unique from CVE-2017-0215, CVE-2017-0216, CVE-2017-0218, and CVE-2017-0219.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Affected Packages5 packages

NVDmicrosoft/windows_101511, 1607+1
CVEListV5microsoft_corporation/microsoft_windowsMicrosoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016.

Patches

🔴Vulnerability Details

5
GHSA
GHSA-476g-vv5c-32cp: Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerabil2022-05-13
GHSA
GHSA-3p2f-6gxq-2j9p: Microsoft Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Gua2022-05-13
GHSA
GHSA-ffhm-frg4-m7jm: Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerabil2022-05-13
GHSA
GHSA-xcx2-x6f7-987c: Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allo2022-05-13
GHSA
GHSA-cpr6-g96h-73qr: Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allo2022-05-13

📋Vendor Advisories

1
Microsoft
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability2017-06-13

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - June 20172017-06-13
CVE-2017-0173 — Resource Exposure | cvebase