CVE-2017-0176

HIGH EXPLOITED

Microsoft Windows Server 2003 - Buffer Overflow

Title source: rule
STIX 2.1

Description

A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98550
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98752
Exploit, Third Party Advisory x_refsource_misc
https://blog.fortinet.com/2017/05/11/deep-analysis-of-esteemaudit

Scores

CVSS v3 8.1
EPSS 0.7019
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-03-12
CWE
CWE-120
Status published
Products (3)
Microsoft/Microsoft Windows Server 2003 SP1, SP2 Windows XP - SP3 Microsoft Windows Server 2003 SP1, SP2 Windows XP - SP3
microsoft/windows_server_2003 (2 CPE variants)
microsoft/windows_xp (4 CPE variants)
Published Jun 22, 2017
Tracked Since Feb 18, 2026