Skip to content

Latest commit

 

History

History
42 lines (30 loc) · 1.95 KB

README_EN.md

File metadata and controls

42 lines (30 loc) · 1.95 KB

CVE-2017-0213

Describe

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability".

ImpactVersion

Product CPU Architecture Version Update Tested
Windows 10 x86/x64
Windows 10 x86/x64 1511
Windows 10 x86/x64 1607
Windows 10 x86/x64 1703
Windows 7 x86/x64 SP1
Windows 8.1 x86/x64
Windows Rt 8.1
Windows Server 2008 x86/x64 SP2
Windows Server 2008 x86/x64 R2 SP1
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016

Patch

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0213

Utilization

CompilerEnvironment

  • VS2019(V120)X64 Release
  • VS2019(V120)X32 Release

Test environment Windows 7 SP1 x64

CVE-2017-0213_win7_x86

Analyze