CVE-2017-0213
KEV RANSOMWAREHIGH 7.3EPSS 84.1%
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.
- CVSS v3.1
- 7.3 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.3 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 84.14% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-28, used in ransomware campaigns
- Published
- 2017-05-12
- Updated
- 2025-10-21
Proof-of-concept exploits (8)
- Anonymous-Family/CVE-2017-02130★ · 2022-01-29
- Itachl/windows_kenel_exploit3★ · 2017-11-01
- billa3283/CVE-2017-02130★ · 2017-10-01
- eonrickity/CVE-2017-021314★ · 2018-04-17
- jbooz1/CVE-2017-02131★ · 2018-03-21
- n8v79a/win-exploit1★ · 2018-06-20
- shaheemirza/CVE-2017-0213-0★ · 2017-06-07
- zcgonvh/CVE-2017-021357★ · 2017-07-01