CVE-2017-8702 is an elevation of privilege vulnerability in Windows Error Reporting (WER) affecting Microsoft Windows 10 (versions Gold, 1511, 1607) and Windows Server 2016. This flaw allows a local attacker with low privileges to gain increased access to sensitive information and system functionality due to WER's file handling. Rated 7.0 HIGH on CVSS, it requires high attack complexity but can lead to high confidentiality, integrity, and availability impacts. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) or KEV listing, it received media coverage and community discussion, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.