CVE-2017-8566
published 2017-07-11CVE-2017-8566: Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improperly…
PriorityP428high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
1.00%
59.5th percentile
Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improperly handling parameters in a method of a DCOM class, aka "Windows IME Elevation of Privilege Vulnerability".
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phv5-9c42-cwvf: Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improper
ghsa_unreviewed·2022-05-13
CVE-2017-8566 [HIGH] CWE-20 GHSA-phv5-9c42-cwvf: Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improper
Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improperly handling parameters in a method of a DCOM class, aka "Windows IME Elevation of Privilege Vulnerability".
Microsoft
Windows IME Elevation of Privilege Vulnerability
vendor_msrc·2017-07-11·CVSS 7.0
CVE-2017-8566 [HIGH] Windows IME Elevation of Privilege Vulnerability
Windows IME Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows Input Method Editor (IME) when IME improperly handles parameters in a method of a DCOM class.
The DCOM server is a Windows component installed regardless of which languages/IMEs are enabled. An attacker can instantiate the DCOM class and exploit the system even if IME is not enabled.
To exploit this vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses this vulnerability by correcting how Windows IME handles parameters in a method of a DCOM class.
Microsoft Windows: Microsoft Windows
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation L
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/99404http://www.securitytracker.com/id/1038853https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8566http://www.securityfocus.com/bid/99404http://www.securitytracker.com/id/1038853https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8566
2017-07-11
Published