CVE-2017-8461 is a remote code execution vulnerability affecting Windows XP and Windows Server 2003 when the Routing and Remote Access service is enabled. An attacker can exploit this flaw by sending a specially crafted application to the RPC server, leading to arbitrary code execution. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires local privileges, but can result in complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, a Metasploit module exists for exploitation, and it has garnered some community discussion and media coverage, including its connection to previously ignored NSA hacking tools.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.