Vulnerability Name: | CVE-2017-8574 (CCN-127654) | ||||||||||||
Assigned: | 2017-07-11 | ||||||||||||
Published: | 2017-07-11 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | Graphics in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8573 and CVE-2017-8556. | ||||||||||||
CVSS v3 Severity: | 7.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-281 | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-8574 Source: BID Type: Third Party Advisory, VDB Entry 99438 Source: CCN Type: BID-99438 Microsoft Windows Graphics Component CVE-2017-8574 Local Privilege Escalation Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1038856 Source: XF Type: UNKNOWN ms-graphics-cve20178574-priv-esc(127654) Source: CCN Type: Microsoft Security TechCenter Security Update Guide - July 2017 Security Updates Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8574 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |