CVE-2017-8716
published 2017-09-13CVE-2017-8716: Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard, due to…
PriorityP424medium5.3CVSS 3.0
AVLACLPRLUINSUCLILAL
EPSS
1.44%
70.5th percentile
Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard, due to the way that Control Flow Guard handles objects in memory, aka "Windows Security Feature Bypass Vulnerability".
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft_corporation | windows_control_flow_guard | — | — |
| msrc | windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmqc-q447-328q: Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard
ghsa_unreviewed·2022-05-13
CVE-2017-8716 [MEDIUM] GHSA-gmqc-q447-328q: Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard
Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard, due to the way that Control Flow Guard handles objects in memory, aka "Windows Security Feature Bypass Vulnerability".
Microsoft
Windows Security Feature Bypass Vulnerability
vendor_msrc·2017-09-12·CVSS 4.9
CVE-2017-8716 [MEDIUM] Windows Security Feature Bypass Vulnerability
Windows Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Windows Control Flow Guard mishandles objects in memory.
To exploit the vulnerability, an attacker could run a specially crafted application to bypass Control Flow Guard.
The security update addresses the vulnerability by correcting how Windows Control Flow Guard handles objects in memory.
Microsoft Windows: Microsoft Windows
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:N/A;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4038788
No detection rules found.
http://www.securityfocus.com/bid/100802http://www.securitytracker.com/id/1039325https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8716http://www.securityfocus.com/bid/100802http://www.securitytracker.com/id/1039325https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8716
2017-09-13
Published