CVE-2017-0104

HIGH

iSNS Server in Windows Server 2008 SP2/R2, 2012 Gold/R2, 2016 - Remote Code Execution via Integer Overflow

Title source: llm
STIX 2.1

Description

The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2, and Windows Server 2016 allows remote attackers to issue malicious requests via an integer overflow, aka "iSNS Server Memory Corruption Vulnerability."

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96697
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038001

Scores

CVSS v3 8.1
EPSS 0.3486
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (6)
microsoft/windows_server_2008
microsoft/windows_server_2008 r2
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
microsoft/windows_server_2016
Microsoft Corporation/iSNS Server The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2
Published Mar 17, 2017
Tracked Since Feb 18, 2026