CVE-2017-0295Corporation Microsoft Windows vulnerability

7 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
0.5%
top 32.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 13

Description

Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-mxrv-wg7h-r74h: Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Wind2022-05-13

📋Vendor Advisories

1
Microsoft
Windows Default Folder Tampering Vulnerability2017-06-13

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - June 20172017-06-13

💬Community

1
Bugzilla
CVE-2017-9806 libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality2017-10-31