Vulnerability Name: | CVE-2017-0104 (CCN-122489) | ||||||||||||
Assigned: | 2016-09-09 | ||||||||||||
Published: | 2017-03-14 | ||||||||||||
Updated: | 2018-10-30 | ||||||||||||
Summary: | The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2, and Windows Server 2016 allows remote attackers to issue malicious requests via an integer overflow, aka "iSNS Server Memory Corruption Vulnerability." | ||||||||||||
CVSS v3 Severity: | 8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-190 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-0104 Source: CCN Type: Microsoft Security Bulletin MS17-012 Security Update for Microsoft Windows (4013078) Source: BID Type: Third Party Advisory, VDB Entry 96697 Source: CCN Type: BID-96697 Microsoft Windows iSNS Server CVE-2017-0104 Memory Corruption Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1038001 Source: XF Type: UNKNOWN ms-windows-cve20170104-code-exec(122489) Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0104 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |