CVE-2017-0295
published 2017-06-15CVE-2017-0295: Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows…
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
1.24%
65.7th percentile
Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability".
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft_corporation | microsoft_windows | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mxrv-wg7h-r74h: Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Wind
ghsa_unreviewed·2022-05-13
CVE-2017-0295 [MEDIUM] GHSA-mxrv-wg7h-r74h: Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Wind
Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability".
Microsoft
Windows Default Folder Tampering Vulnerability
vendor_msrc·2017-06-13·CVSS 4.8
CVE-2017-0295 [MEDIUM] Windows Default Folder Tampering Vulnerability
Windows Default Folder Tampering Vulnerability
Description: A tampering vulnerability exists in Microsoft Windows that could allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure. An attacker who successfully exploited this vulnerability could potentially modify files and folders that are synchronized the first time when a user logs in locally to the computer.
To exploit this vulnerability, an attacker would need to log on to the affected system and tamper with the DEFAULT folder contents. An attacker can only exploit this vulnerability prior to a user logging on locally to the computer. Users who have logged on before the attacker attempts to exploit this vulnerability would not be affected.
The security update addresses the vulnerability by correcting permissio
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - June 2017
blogs_talos·2017-06-13·CVSS 8.8
CVE-2017-0283 [HIGH] Microsoft Patch Tuesday - June 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 92 vulnerabilities with 17 of them rated critical and 75 rated important. Impacted products include Edge, Internet Explorer, Office, Sharepoint, Skype for Business, Lync, and Windows.
### Vulnerabilities Rated Critical
#### CVE-2017-0283 This is a remote code execution vulnerability in Windows Uniscribe related to improper handling of objects in memory. The attack can result in the attacker gaining full control of the affected system. This can be exploited through multiple vectors including viewing a specially crafted website or a user opening a specially crafted document file.
#### CVE-2017-0291 / CVE-2017-0292 These are remote code execution vulnerabil
Bugzilla
CVE-2017-9806 libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality
bugzilla·2017-10-31·CVSS 7.8
CVE-2017-9806 [HIGH] CVE-2017-9806 libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality
CVE-2017-9806 libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality
An exploitable out of bound write vulnerability exists in the WW8Fonts::WW8Fonts functionality of Apache OpenOffice 4.1.3. A specially crafted doc file can cause an out of bound write potentially resulting in arbitrary code execution. An attacker can send/provide a malicious doc file to trigger this vulnerability.
External References:
https://www.talosintelligence.com/reports/TALOS-2017-0295
https://www.openoffice.org/security/cves/CVE-2017-9806.html
https://www.libreoffice.org/about-us/security/advisories/CVE-2017-9806
Discussion:
Created libreoffice tracking bugs for this issue:
Affects: fedora-all [bug 1507808]
---
Is there any reproducer? Or even a hint whether libreoffice is vulnerable too?
http://www.securityfocus.com/bid/98904http://www.securitytracker.com/id/1038674https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0295http://www.securityfocus.com/bid/98904http://www.securitytracker.com/id/1038674https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0295
2017-06-15
Published