CVE-2017-8716Corporation Windows Control Flow Guard vulnerability

5 documents5 sources
Severity
5.3MEDIUMNVD
EPSS
2.3%
top 15.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateMay 13

Description

Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard, due to the way that Control Flow Guard handles objects in memory, aka "Windows Security Feature Bypass Vulnerability".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-gmqc-q447-328q: Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard2022-05-13

💥Exploits & PoCs

1
Exploit-DB
WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting2018-04-24

📋Vendor Advisories

1
Microsoft
Windows Security Feature Bypass Vulnerability2017-09-12

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - September 20172017-09-12