CVE-2017-11782 is an elevation of privilege vulnerability affecting Microsoft Windows 10 version 1607 and Windows Server 2016, stemming from specially crafted requests sent to the Server Message Block (SMB) service. With a CVSS score of 7.8 (High), it allows a local attacker to gain high confidentiality, integrity, and availability impact with low attack complexity. While the vulnerability is not listed in CISA's KEV catalog and lacks public exploit code on platforms like Metasploit or ExploitDB, it has garnered some community discussion and media coverage. Its EPSS score is low, suggesting a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.