CVE-2017-8467 is an Elevation of Privilege vulnerability in the Graphics component of multiple Microsoft Windows versions, including Windows 7, 8.1, 10, and various Server editions. This flaw stems from how the operating system handles objects in memory, potentially allowing a local attacker to gain elevated privileges. With a CVSS score of 7.0 (High), exploitation requires low privileges and high attack complexity, but successful attacks could lead to high impact on confidentiality, integrity, and availability. While the vulnerability has garnered some community discussion and media coverage, there is no evidence of active exploitation, nor are public exploit codes like Metasploit or ExploitDB modules available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.