CVE-2017-0295 — Corporation Microsoft Windows vulnerability
7 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
0.5%
top 32.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 15
Latest updateMay 13
Description
Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability".
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages7 packages
▶CVEListV5microsoft_corporation/microsoft_windowsMicrosoft Windows 10 1607 and 1703, and Windows Server 2016.
Patches
🔴Vulnerability Details
1GHSA▶
GHSA-mxrv-wg7h-r74h: Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Wind↗2022-05-13
📋Vendor Advisories
1🕵️Threat Intelligence
1💬Community
1Bugzilla
▶