CVE-2017-8579Improper Preservation of Permissions in Corporation Microsoft Windows

Severity
7.0HIGHNVD
EPSS
0.7%
top 28.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 29
Latest updateMay 13

Description

The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "DirectX Elevation of Privilege Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages11 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-m26g-pfvj-g9mg: The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code i2022-05-13

📋Vendor Advisories

1
Microsoft
DirectX Elevation of Privilege Vulnerability2017-06-13

🕵️Threat Intelligence

2
Unit42
Sure, I’ll take that! New ComboJack Malware Alters Clipboards to Steal Cryptocurrency2018-03-05
Unit42
Sure, I’ll take that! New ComboJack Malware Alters Clipboards to Steal Cryptocurrency2018-03-05
CVE-2017-8579 — Improper Preservation of Permissions | cvebase