CVE-2017-8465 is an Elevation of Privilege vulnerability affecting multiple versions of Microsoft Windows, including Windows 8.1, Windows 10, Windows Server 2012 R2, and Windows Server 2016. This flaw allows an attacker to execute processes with elevated privileges due to improper handling of objects in memory by the Windows kernel (Win32k). The vulnerability has a CVSS v3 score of 7.8 (High), indicating a local attack vector with low attack complexity, requiring low privileges and no user interaction. A successful exploit could lead to high impact on confidentiality, integrity, and availability of the affected system. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:* | ||
rtCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:rt:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.