CVE-2017-0708
published 2017-07-06CVE-2017-0708: A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.
PriorityP420medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
0.41%
33.0th percentile
A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2h2v-8cgx-wfvj: A information disclosure vulnerability in the HTC sound driver
ghsa_unreviewed·2022-05-17
CVE-2017-0708 [MEDIUM] CWE-200 GHSA-2h2v-8cgx-wfvj: A information disclosure vulnerability in the HTC sound driver
A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.
Android
CVE-2017-0708: Sound driver
vendor_android·2017-07-01·CVSS 5.5
CVE-2017-0708 [MEDIUM] CVE-2017-0708: Sound driver
Android Security Bulletin 2017-07-01
CVE: CVE-2017-0708
Severity: MEDIUM
Type: ID
Component: Sound driver
References: A-35384879*
No detection rules found.
No public exploits indexed.
Talos
Talos releases coverage for 'wormable' Microsoft vulnerability
blogs_talos·2019-05-21·CVSS 9.8
CVE-2019-0708 [CRITICAL] Talos releases coverage for 'wormable' Microsoft vulnerability
Last night, Cisco Talos released the latest SNORT® rule update, which includes coverage for the critical Microsoft vulnerability CVE-2019-0708.
The company disclosed this vulnerability last week as part of its monthly security update. This particular bug exists in Remote Desktop Services — formerly known as Terminal Services.
The vulnerability requires no user interaction and is pre-authentication. Microsoft specifically warned against this bug because it is "wormable," meaning future malware that exploits this vulnerability could spread from system to system. One of the most infamous examples of a worm was the WannaCry malware, which disabled major services across the globe in May 2017. An attacker could exploit this vulnerability by sending a specially crafted request to the target sys
Talos
Talos releases coverage for 'wormable' Microsoft vulnerability
blogs_talos·2019-05-21·CVSS 9.8
CVE-2019-0708 [CRITICAL] Talos releases coverage for 'wormable' Microsoft vulnerability
## Talos releases coverage for 'wormable' Microsoft vulnerability
Last night, Cisco Talos released the latest SNORT® rule update , which includes coverage for the critical Microsoft vulnerability CVE-2019-0708.
The company disclosed this vulnerability last week as part of its monthly security update . This particular bug exists in Remote Desktop Services — formerly known as Terminal Services.
The vulnerability requires no user interaction and is pre-authentication. Microsoft specifically warned against this bug because it is "wormable," meaning future malware that exploits this vulnerability could spread from system to system. One of the most infamous examples of a worm was the WannaCry malware , which disabled major services across the globe in May 2017. An attacker could exploit this
Krebs
Microsoft Patches ‘Wormable’ Flaw in Windows XP, 7 and Windows 2003
blogs_krebs·2019-05-14·CVSS 9.8
CVE-2019-0708 [CRITICAL] Microsoft Patches ‘Wormable’ Flaw in Windows XP, 7 and Windows 2003
Microsoft today is taking the unusual step of releasing security updates for unsupported but still widely-used Windows operating systems like XP and Windows 2003 , citing the discovery of a “wormable” flaw that the company says could be used to fuel a fast-moving malware threat like the WannaCry ransomware attacks of 2017.
The May 2017 global malware epidemic WannaCry affected some 200,000 Windows systems in 150 countries. Source: Wikipedia.
The vulnerability ( CVE-2019-0708 ) resides in the “remote desktop services” component built into supported versions of Windows, including Windows 7 , Windows Server 2008 R2 , and Windows Server 2008 . It also is present in computers powered by Windows XP and Windows 2003, operating systems for which Microsoft long ago stopped shipping security updat
Krebs
Microsoft Patches ‘Wormable’ Flaw in Windows XP, 7 and Windows 2003
blogs_krebs·2019-05-14·CVSS 9.8
CVE-2019-0708 [CRITICAL] Microsoft Patches ‘Wormable’ Flaw in Windows XP, 7 and Windows 2003
Microsoft today is taking the unusual step of releasing security updates for unsupported but still widely-used Windows operating systems like XP and Windows 2003, citing the discovery of a “wormable” flaw that the company says could be used to fuel a fast-moving malware threat like the WannaCry ransomware attacks of 2017.
The vulnerability (CVE-2019-0708) resides in the “remote desktop services” component built into supported versions of Windows, including Windows 7, Windows Server 2008 R2, and Windows Server 2008. It also is present in computers powered by Windows XP and Windows 2003, operating systems for which Microsoft long ago stopped shipping security updates.
Microsoft said the company has not yet observed any evidence of attacks against the dangerous security flaw, but that it is
2017-07-06
Published