CVE-2017-0101 is a critical elevation of privilege vulnerability affecting kernel-mode drivers in Microsoft Windows Vista through Windows 10 and Windows Server 2008 through 2016. A local attacker can exploit this flaw via a crafted application to gain elevated privileges on the system. With a CVSS score of 7.8 (High) and a FAUCET Risk Score of 100/100, this vulnerability allows for complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, including in known ransomware campaigns, and exploit code is publicly available, indicating a high and immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.