CVE-2017-11829
published 2017-10-13CVE-2017-11829: Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share…
PriorityP428medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
3.78%
88.9th percentile
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft_corporation | microsoft_windows_10 | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Update Delivery Optimization Elevation of Privilege Vulnerability
vendor_msrc·2017-10-10·CVSS 5.5
CVE-2017-11829 [MEDIUM] Windows Update Delivery Optimization Elevation of Privilege Vulnerability
Windows Update Delivery Optimization Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions. An attacker who successfully exploited the vulnerability could overwrite files that require higher privileges than what the attacker already has.
To exploit this vulnerability, an attacker would need to log into a system. The attacker could then create a Delivery Optimization job to exploit the vulnerability.
The security update addresses the vulnerability by correcting how the Delivery Optimization services enforces permissions.
Windows Update: Windows Update
Issuing CNA: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploite
GHSA
GHSA-rvcj-88m8-gcj3: Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share
ghsa_unreviewed·2022-05-13
CVE-2017-11829 [MEDIUM] CWE-552 GHSA-rvcj-88m8-gcj3: Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/101213http://www.securitytracker.com/id/1039526https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11829http://www.securityfocus.com/bid/101213http://www.securitytracker.com/id/1039526https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11829
2017-10-13
Published