⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2022-04-18.

CVE-2017-0213Corporation Windows COM vulnerability

22 documents17 sources
Severity
7.3HIGHNVD
NVD7.0
EPSS
92.7%
top 0.25%
CISA KEV
KEVRansomware
Added 2022-03-28
Due 2022-04-18
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMay 12
KEV addedMar 28
KEV dueApr 18
Latest updateFeb 12
CISA Required Action: Apply updates per vendor instructions.

Description

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages15 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6pc8-xvmj-x3wh: Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 82022-05-13
GHSA
GHSA-8cpc-fr8p-99pq: Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 82022-05-13
VulnCheck
Microsoft Windows Privilege Escalation Vulnerability2017

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - COM Aggregate Marshaler/IRemUnknown2 Type Confusion Privilege Escalation2017-05-17

📋Vendor Advisories

2
CISA
Microsoft Windows Privilege Escalation Vulnerability2022-03-28
Microsoft
Windows COM Elevation of Privilege Vulnerability2017-05-09

🕵️Threat Intelligence

13
Bleepingcomputer
Privilege elevation exploits used in over 50% of insider attacks2023-12-08
Unit42
Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor2023-06-28
Unit42
Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor2023-06-28
Sentinelone
Ragnar Locker2022-11-30
Fortinet
Ransomware Roundup: Ragnar Locker Ransomware | FortiGuard Labs2022-09-17

📄Research Papers

1
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures2025-02-12
CVE-2017-0213 — Corporation Windows COM vulnerability | cvebase