CVE-2017-8694 is an elevation of privilege vulnerability in the Microsoft Windows Kernel Mode Driver, affecting numerous Windows client and server operating systems including Windows 7, 8.1, 10, and Server 2008 through 2016. This flaw stems from improper handling of objects in memory, allowing a local attacker to gain elevated privileges. With a CVSS score of 7.0 (High), exploitation requires low privileges but high attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While it was patched as part of Microsoft's October 2017 Patch Tuesday, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.