CVE-2017-0001 is an Elevation of Privilege vulnerability in the Microsoft Windows Graphics Device Interface (GDI) component, affecting various Windows versions including Windows 7, 8.1, 10, Vista, and Server editions. With a CVSS score of 7.8 (High), this vulnerability allows a local attacker to gain elevated privileges through a crafted application, requiring low attack complexity and user interaction. This vulnerability is known to be actively exploited in the wild, as indicated by its presence in the CISA KEV catalog and media reports linking it to Russian state-sponsored cyberespionage. Despite active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is not readily available, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.