CVE-2017-0189
published 2017-04-12CVE-2017-0189: An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who…
PriorityP341high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
2.05%
79.1th percentile
An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode, aka "Win32k Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0188.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | windows | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Win32k Elevation of Privilege Vulnerability
vendor_msrc·2017-04-11·CVSS 7.8
CVE-2017-0189 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
Windows Kernel-Mode Drivers: Windows Kernel-Mode D
GHSA
GHSA-g9w7-8hcr-36c9: A Win32k information disclosure vulnerability exists in Windows 8
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2017-0188 [HIGH] CWE-200 GHSA-g9w7-8hcr-36c9: A Win32k information disclosure vulnerability exists in Windows 8
A Win32k information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0189.
GHSA
GHSA-gm7p-c8p7-9785: An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory
ghsa_unreviewed·2022-05-13·CVSS 3.3
CVE-2017-0189 [LOW] GHSA-gm7p-c8p7-9785: An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory
An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode, aka "Win32k Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0188.
Suricata
ET EXPLOIT CVE-2016-0189 Exploit HFS Actor
suricata·2017-09-07·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT CVE-2016-0189 Exploit HFS Actor
ET EXPLOIT CVE-2016-0189 Exploit HFS Actor
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2016-0189 Exploit HFS Actor"; flow:established,to_client; http.server; content:"HFS"; startswith; file.data; content:"triggerBug"; nocase; fast_pattern; content:"exploit"; nocase; content:"intToStr"; nocase; content:"strToInt"; nocase; classtype:trojan-activity; sid:2024677; rev:4; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_09_07, cve CVE_2016_0189, deployment Perimeter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07;)
Suricata
ET EXPLOIT CVE-2016-0189 Exploit
suricata·2017-09-07·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT CVE-2016-0189 Exploit
ET EXPLOIT CVE-2016-0189 Exploit
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2016-0189 Exploit"; flow:established,to_client; file.data; content:"triggerBug"; nocase; fast_pattern; pcre:"/^\s*(?:\x28|\%28)/Rs"; content:"exploit"; nocase; pcre:"/^\s*(?:\x28|\%28)o/Rs"; content:"intToStr"; nocase; pcre:"/^\s*(?:\x28|\%28)x/Rs"; content:"strToInt"; nocase; pcre:"/^\s*(?:\x28|\%28)s/Rs"; classtype:trojan-activity; sid:2024676; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_09_07, cve CVE_2016_0189, deployment Perimeter, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
suricata·2017-04-04·CVSS 8.8
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit"; flow:established,to_client; file.data; content:"EB125831C966B9"; nocase; content:"05498034088485C975F7FFE0E8E9FFFFFFD10D61074028D7D5D3B544E0"; distance:2; within:58; nocase; reference:cve,2016-0189; classtype:exploit-kit; sid:2024170; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_04_04, cve CVE_2016_0189, deployment Perimeter, malware_family Exploit_Kit_Terror, performance_impact Low, confidence High, signature_severity Major, tag Exploit_Kit_Terror, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit M2
suricata·2017-04-04·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit M2
ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit M2"; flow:established,to_client; file.data; content:"|73 74 72 54 6f 49 6e 74 28 4d 69 64 28 6d 65 6d 2c 20 31 2c 20 32 29 29|"; content:"|2b 20 26 48 31 37 34|"; reference:cve,2016-0189; classtype:exploit-kit; sid:2024169; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_04_04, cve CVE_2016_0189, deployment Perimeter, malware_family Exploit_Kit_Terror, performance_impact Low, confidence High, signature_severity Major, tag Exploit_Kit_Terror, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit
suricata·2017-04-04·CVSS 7.5
CVE-2016-0189 [HIGH] ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit
ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Terror EK CVE-2016-0189 Exploit"; flow:established,to_client; file.data; content:"dllcode"; nocase; fast_pattern; content:"|28 26 68 34 64 2c 26 68 35 61 2c 26 68 38 30 2c 30 2c 31 2c 30 2c 30 2c 30|"; nocase; content:"GetSpecialFolder"; nocase; reference:cve,2016-0189; classtype:exploit-kit; sid:2024168; rev:4; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2017_04_04, cve CVE_2016_0189, deployment Perimeter, malware_family Exploit_Kit_Terror, performance_impact Low, confidence High, signature_severity Major, tag Exploit_Kit_Terror, tag CISA_KEV, updated_at 2024_03_14;)
No public exploits indexed.
Talos
Microsoft Patch Tuesday - April 2017
blogs_talos·2017-04-12·CVSS 7.8
CVE-2017-0106 [HIGH] Microsoft Patch Tuesday - April 2017
## Microsoft Patch Tuesday - April 2017
It’s that time again! Today we bring you April’s Microsoft Patch Tuesday information. These fixed vulnerabilities affect Outlook, Edge, Internet Explorer, Hyper-V, .NET, and Scripting Engine.
## Bulletins Rated Critical
CVE-2017-0106 outlines a vulnerability in Microsoft Word. It permits the bypass of security features when document loading is done via Outlook attachments for certain crafted emails. Successful exploitation of this issue may grant an attacker remote code execution.
CVE-2017-0158 details a vulnerability caused by certain malicious HTML files with VBScript content. Successful exploitation of this issue may grant an attacker remote code execution.
CVE-2017-0160 outlines a compromised WMI server accessed over DCOM using System.Manage
Talos
Microsoft Patch Tuesday - April 2017
blogs_talos·2017-04-12·CVSS 7.8
CVE-2017-0106 [HIGH] Microsoft Patch Tuesday - April 2017
It’s that time again! Today we bring you April’s Microsoft Patch Tuesday information. These fixed vulnerabilities affect Outlook, Edge, Internet Explorer, Hyper-V, .NET, and Scripting Engine.
### Bulletins Rated Critical
CVE-2017-0106 outlines a vulnerability in Microsoft Word. It permits the bypass of
security features when document loading is done via Outlook attachments for
certain crafted emails. Successful exploitation of this issue may grant an
attacker remote code execution.
CVE-2017-0158 details a vulnerability caused by certain malicious HTML files with VBScript content. Successful exploitation of this issue may grant an attacker remote code execution.
CVE-2017-0160 outlines a compromised WMI server accessed over DCOM using System.Management classes or the Powershell Get-WmiOb
Recorded Future
Microsoft Office Tops the Exploit Charts
blogs_recorded_future·CVSS 7.8
CVE-2017-0199 [HIGH] Microsoft Office Tops the Exploit Charts
# Microsoft Office Tops the Exploit Charts
### Key Takeaways
- Recorded Future research shows that seven of the top 10 vulnerabilities exploited in 2017 targeted Microsoft products.
- At least two of these, CVE-2017-0199 and CVE-2017-0189, were critical vulnerabilities — their exploitation allowed threat actors to arbitrarily execute code or access and change data.
- Despite being aware of at least some of these vulnerabilities for many months, Microsoft did not immediately patch them, leaving users exposed. Patches were not released until after exploits targeting those vulnerabilities appeared for sale on the dark web.
- The pattern and timeline of vulnerability recognition and response shows that proprietors like Microsoft do not always disclose information about existing cybersecurity
Recorded Future
Microsoft Office Tops the Exploit Charts | Recorded Future
blogs_recorded_future·CVSS 7.8
CVE-2017-0199 [HIGH] Microsoft Office Tops the Exploit Charts | Recorded Future
## Microsoft Office Tops the Exploit Charts
## Key Takeaways
Recorded Future research shows that seven of the top 10 vulnerabilities exploited in 2017 targeted Microsoft products.
At least two of these, CVE-2017-0199 and CVE-2017-0189, were critical vulnerabilities — their exploitation allowed threat actors to arbitrarily execute code or access and change data.
Despite being aware of at least some of these vulnerabilities for many months, Microsoft did not immediately patch them, leaving users exposed. Patches were not released until after exploits targeting those vulnerabilities appeared for sale on the dark web.
The pattern and timeline of vulnerability recognition and response shows that proprietors like Microsoft do not always disclose information about existing cybersecurity thre
Zscaler
Zscaler protects against 16 new vulnerabilities for MS
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler protects against 16 new vulnerabilities for MS
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/97420http://www.securitytracker.com/id/1038239https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0189http://www.securityfocus.com/bid/97420http://www.securitytracker.com/id/1038239https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0189
2017-04-12
Published