CVE-2017-0213

HIGH KEV RANSOMWARE

Microsoft Windows - Privilege Escalation

Title source: llm

Description

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.

Exploits (10)

nomisec WRITEUP 58 stars
by zcgonvh · local
https://github.com/zcgonvh/CVE-2017-0213
nomisec SUSPICIOUS 13 stars
by eonrickity · poc
https://github.com/eonrickity/CVE-2017-0213
nomisec WRITEUP 1 stars
by jbooz1 · local
https://github.com/jbooz1/CVE-2017-0213
nomisec SUSPICIOUS
by shaheemirza · poc
https://github.com/shaheemirza/CVE-2017-0213-
nomisec WRITEUP
by Anonymous-Family · poc
https://github.com/Anonymous-Family/CVE-2017-0213
nomisec STUB
by billa3283 · poc
https://github.com/billa3283/CVE-2017-0213
patchapalooza WRITEUP
by Ascotbe · local
https://github.com/Ascotbe/Kernelhub
exploitdb WRITEUP VERIFIED
by Google Security Research · c++localwindows
https://www.exploit-db.com/exploits/42020

Scores

CVSS v3 7.3
EPSS 0.9269
EPSS Percentile 99.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-03-28
VulnCheck KEV 2018-12-21
InTheWild.io 2020-05-27
ENISA EUVD EUVD-2017-0579
Ransomware Use Confirmed

Classification

Status draft

Affected Products (12)

microsoft/windows_10_1507
microsoft/windows_10_1511
microsoft/windows_10_1607
microsoft/windows_10_1703
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_2008
microsoft/windows_server_2008
microsoft/windows_server_2012
microsoft/windows_server_2012
microsoft/windows_server_2016

Timeline

Published May 12, 2017
KEV Added Mar 28, 2022
Tracked Since Feb 18, 2026