CVE-2017-11818
published 2017-10-13CVE-2017-11818: The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows…
PriorityP421medium4.5CVSS 3.0
AVLACHPRLUINSUCLILAL
EPSS
1.17%
64.2th percentile
The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level check, aka "Windows Storage Security Feature Bypass Vulnerability".
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | microsoft_windows_storage | — | — |
| msrc | windows_10_for_32-bit_systems | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.04.5MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Storage Security Feature Bypass Vulnerability
vendor_msrc·2017-10-10·CVSS 4.5
CVE-2017-11818 [MEDIUM] Windows Storage Security Feature Bypass Vulnerability
Windows Storage Security Feature Bypass Vulnerability
Description: An Security Feature bypass vulnerability exists in Microsoft Windows storage when it fails to validate an integrity-level check.
An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity level.
The update addresses the vulnerability by correcting how Microsoft storage validates an integrity-level check.
Microsoft Windows: Microsoft Windows
Issuing CNA: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4041
GHSA
GHSA-v5cx-4469-frm4: The Microsoft Windows Storage component on Microsoft Windows 8
ghsa_unreviewed·2022-05-14
CVE-2017-11818 [MEDIUM] GHSA-v5cx-4469-frm4: The Microsoft Windows Storage component on Microsoft Windows 8
The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level check, aka "Windows Storage Security Feature Bypass Vulnerability".
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/101101http://www.securitytracker.com/id/1039526https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11818http://www.securityfocus.com/bid/101101http://www.securitytracker.com/id/1039526https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11818
2017-10-13
Published