98103vdb entry
http://www.securityfocus.com/bid/98103 CVE-2017-0214
HIGH
Microsoft Windows - Running Object Table Register ROTFLAGS_ALLOWANYCLIENT Privilege Escalation
Record summary
CVE-2017-0214 has a selected CVSS score of 7.0 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when Windows fails to properly validate input before loading type libraries, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0213.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Windows COMBrowse Microsoft Corporation / Windows COM | CVE List | Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016. | affected |
Proofs of concept
2Catalogued exploits
ExploitDBMicrosoft Windows - Running Object Table Register ROTFLAGS_ALLOWANYCLIENT Privilege EscalationExploitDB exploitby Google Security ResearchNot analyzed1 file
Repository PoCs
GitHubAnonymous-Family/CVE-2017-0213Repository PoCby Anonymous-FamilyStars: 0Not analyzed3 files
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-0214 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0214 42021exploit
https://www.exploit-db.com/exploits/42021