PoC Index

CVE-2017-0213

KEV RANSOMWAREHIGH 7.3EPSS 84.1%

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.

CVSS v3.1
7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
1.9 LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
EPSS
84.14% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-03-28, used in ransomware campaigns
Published
2017-05-12
Updated
2025-10-21

Proof-of-concept exploits (8)

ExploitDB entries (1)

Exploit collections (1)

References

Related