9.3
CVSSv2

CVE-2017-8487

Published: 15/06/2017 Updated: 03/10/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Windows OLE in Windows XP and Windows Server 2003 allows an malicious user to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2003 -

microsoft windows xp -

Exploits

/* Source: bugschromiumorg/p/project-zero/issues/detail?id=1147 We have discovered that the IOCTL sent to the \Device\KsecDD device by the BCryptOpenAlgorithmProvider documented API returns some uninitialized pool memory in the output buffer Let's consider the following input data for the IOCTL: --- cut --- 00000000: 4d 3c 2b 1a 00 00 ...