Microsoft Windows Graphics CVE-2017-0005 Local Privilege Escalation Vulnerability
by CIRT Team
Description: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka “Windows GDI Elevation of Privilege Vulnerability.” This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0025, and CVE-2017-0047
Impact: A local attacker can exploit this issue to execute arbitrary code within the context of the kernel privileges.
Mitigation: Updates are available. Please check specific vendor advisory for more information.
Reference URL’s:
- http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0005
- https://support.microsoft.com/en-us/help/4013075/ms17-013-security-update-for-microsoft-graphics-component-march-14-201
- https://technet.microsoft.com/library/security/MS17-013
- https://blogs.technet.microsoft.com/mmpc/2017/03/27/detecting-and-mitigating-elevation-of-privilege-exploit-for-cve-2017-0005/
- http://www.securityfocus.com/bid/96033/discuss
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts