Vulnerability Name: | CVE-2017-0164 (CCN-123868) | ||||||||||||
Assigned: | 2016-09-09 | ||||||||||||
Published: | 2017-04-11 | ||||||||||||
Updated: | 2017-07-11 | ||||||||||||
Summary: | A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability." | ||||||||||||
CVSS v3 Severity: | 4.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H) 3.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
3.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-0164 Source: BID Type: Third Party Advisory, VDB Entry 97448 Source: CCN Type: BID-97448 Microsoft Windows Active Directory CVE-2017-0164 Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1038235 Source: XF Type: UNKNOWN ms-ad-cve20170164-dos(123868) Source: CCN Type: Microsoft Security Tech Center Security Update Guide Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0164 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |