CVE-2017-8703
published 2017-10-13CVE-2017-8703: The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in memory…
PriorityP421medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
1.68%
74.4th percentile
The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability".
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft_corporation | windows_subsystem_for_linux | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_msrc5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Subsystem for Linux Denial of Service Vulnerability
vendor_msrc·2017-10-10·CVSS 5.0
CVE-2017-8703 [MEDIUM] Windows Subsystem for Linux Denial of Service Vulnerability
Windows Subsystem for Linux Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory. An attacker who successfully exploited this vulnerability could cause a denial of service against the local system.
A attacker could exploit this vulnerability by running a specially crafted application.
The update addresses the vulnerability by correcting how Windows Subsystem for Linux handles objects in memory.
Windows Subsystem for Linux: Windows Subsystem for Linux
Issuing CNA: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:N/A;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/
GHSA
GHSA-532m-9cc8-mggr: The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in
ghsa_unreviewed·2022-05-17
CVE-2017-8703 [MEDIUM] CWE-119 GHSA-532m-9cc8-mggr: The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in
The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability".
No detection rules found.
No public exploits indexed.
Krebs
Microsoft’s October Patch Batch Fixes 62 Flaws
blogs_krebs·2017-10-11·CVSS 7.5
[HIGH] Microsoft’s October Patch Batch Fixes 62 Flaws
Microsoft on Tuesday released software updates to fix at least 62 security vulnerabilities in Windows , Office and other software. Two of those flaws were detailed publicly before yesterday’s patches were released, and one of them is already being exploited in active attacks, so attackers already have a head start.
Roughly half of the flaws Microsoft addressed this week are in the code that makes up various versions of Windows, and 28 of them were labeled “critical” — meaning malware or malicious attackers could use the weaknesses to break into Windows computers remotely with no help from users.
One of the publicly disclosed Windows flaws ( CVE-2017-8703 ) fixed in this batch is a problem with a feature only present in Windows 10 known as the Windows Subsystem for Linux , which allows Wi
Krebs
Microsoft’s October Patch Batch Fixes 62 Flaws
blogs_krebs·2017-10-11·CVSS 7.5
CVE-2017-8703 [HIGH] Microsoft’s October Patch Batch Fixes 62 Flaws
Microsoft on Tuesday released software updates to fix at least 62 security vulnerabilities in Windows, Office and other software. Two of those flaws were detailed publicly before yesterday’s patches were released, and one of them is already being exploited in active attacks, so attackers already have a head start.
One of the publicly disclosed Windows flaws (CVE-2017-8703) fixed in this batch is a problem with a feature only present in Windows 10 known as the Windows Subsystem for Linux, which allows Windows 10 users to run unmodified Linux binary files. Researchers at CheckPoint recently released some interesting research worth reading about how attackers might soon use this capability to bypass antivirus and other security solutions on Windows.
The bug quashed this week that’s being ac
Talos
Microsoft Patch Tuesday - October 2017
blogs_talos·2017-10-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - October 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 63 new vulnerabilities with 28 of them rated critical and 35 rated important. These vulnerabilities impact Graphics, Edge, Internet Explorer, Office, Sharepoint, Windows Graphic Display Interface, Windows Kernel Mode Drivers, and more.
## Vulnerabilities Rated CriticalThe following vulnerabilities are rated "Critical" by Microsoft:
- CVE-2017-11813 - Internet Explorer Memory Corruption Vulnerability
- CVE-2017-11822 - Internet Explorer Memory Corruption Vulnerability
- CVE-2017-11762 - Microsoft Graphics Remote Code Execution Vulnerability
- CVE-2017-11763 - Microsoft Graphics Remote Code Execution Vulnerabi
Bugzilla
CVE-2017-14159 openldap: Privilege escalation via PID file manipulation
bugzilla·2017-09-06·CVSS 4.7
CVE-2017-14159 [MEDIUM] CVE-2017-14159 openldap: Privilege escalation via PID file manipulation
CVE-2017-14159 openldap: Privilege escalation via PID file manipulation
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.
This represents a minor security issue; additional factors are needed to make it exploitable.
References:
http://www.openldap.org/its/index.cgi?findid=8703
Discussion:
Created openldap tracking bugs for this issue:
Affects: fedora-all [bug 1488752]
---
As per upstream:
"If I understood you correctly, "Additional factors are needed" basically means you have to find a code execu
Bugzilla
CVE-2016-8685 CVE-2016-8686 CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 CVE-2016-8697 CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 CVE-2017-7263 potrace: Multiple
bugzilla·2016-10-17·CVSS 5.5
CVE-2016-8685 [MEDIUM] CVE-2016-8685 CVE-2016-8686 CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 CVE-2016-8697 CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 CVE-2017-7263 potrace: Multiple
CVE-2016-8685 CVE-2016-8686 CVE-2016-8694 CVE-2016-8695 CVE-2016-8696 CVE-2016-8697 CVE-2016-8698 CVE-2016-8699 CVE-2016-8700 CVE-2016-8701 CVE-2016-8702 CVE-2016-8703 CVE-2017-7263 potrace: Multiple security issues
Multiple issues in potrace were assigned CVEs on oss-security.
References:
http://seclists.org/oss-sec/2016/q4/153
https://blogs.gentoo.org/ago/2016/08/08/potrace-multiple-three-null-pointer-dereference-in-bm_readbody_bmp-bitmap_io-c/
AddressSanitizer: SEGV on unknown address 0x4f027b in bm_readbody_bmp /var/tmp/portage/media-gfx/potrace-1.12/work/potrace-1.12/src/bitmap_io.c:717:4
Use CVE-2016-8694.
AddressSanitizer: SEGV on unknown address 0x4f0957 in bm_readbody_bmp /var/tmp/portage/media-gfx/potrace-1.12/work/potrace-1.12/src/bitmap_io.c:744:4
Use CVE-2016-8695.
http://www.securityfocus.com/bid/101164http://www.securitytracker.com/id/1039534https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8703http://www.securityfocus.com/bid/101164http://www.securitytracker.com/id/1039534https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8703
2017-10-13
Published