CVE-2017-0100 is an Elevation of Privilege vulnerability in a DCOM object within Helppane.exe, affecting various Microsoft Windows client and server operating systems, including Windows 7, 8.1, 10, and Server 2008 R2 through 2016. Rated High with a CVSS score of 7.8, this flaw allows a local, low-privileged attacker to gain full system privileges with low attack complexity. The potential impact is high across confidentiality, integrity, and availability. While not listed in CISA KEV, public exploit code is available on platforms like ExploitDB. Its high EPSS score of 0.50348 indicates a significant probability of exploitation, and it has a high FAUCET Risk Score of 74.0/100, alongside active community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.