Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-0158


An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."


Published

2017-04-12T14:59:00.327

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

4.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System microsoft windows_10 * Yes
Operating System microsoft windows_10 1511 Yes
Operating System microsoft windows_10 1607 Yes
Operating System microsoft windows_10 1703 Yes
Operating System microsoft windows_7 * Yes
Operating System microsoft windows_8.1 * Yes
Operating System microsoft windows_rt_8.1 * Yes
Operating System microsoft windows_server_2008 * Yes
Operating System microsoft windows_server_2008 r2 Yes
Operating System microsoft windows_server_2012 * Yes
Operating System microsoft windows_server_2012 r2 Yes
Operating System microsoft windows_server_2016 * Yes
Operating System microsoft windows_vista * Yes

References