CVE-2017-11829Files or Directories Accessible to External Parties in Corporation Microsoft Windows 10

Severity
5.5MEDIUMNVD
EPSS
2.3%
top 15.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 13

Description

Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

NVDmicrosoft/windows_101607, 1703+1
CVEListV5microsoft_corporation/microsoft_windows_10Windows 10 version 1607, Windows 10 version 1703 and Windows Server 2016

Patches

🔴Vulnerability Details

1
GHSA
GHSA-rvcj-88m8-gcj3: Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share2022-05-13

📋Vendor Advisories

1
Microsoft
Windows Update Delivery Optimization Elevation of Privilege Vulnerability2017-10-10

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - October 20172017-10-10