ZeroHour

CVE-2017-0001

KEVmass

Local Privilege Escalation in Microsoft Windows GDI

CISA: Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p87
Published
()
KEV added
AI analysis

CVE-2017-0001 is a privilege escalation flaw in the Windows Graphics Device Interface (GDI) that affects Windows Vista through Windows 10 (1507, 1511, 1607) and Windows Server 2008 through 2016. It is triggered by a local attacker who runs a crafted application on an affected system, requiring only low local privileges and no user interaction. Successful exploitation grants the attacker elevated privileges, with high impact on confidentiality, integrity and availability, effectively giving full control of the host. Any organization running unpatched copies of these Windows client or server versions is affected. The flaw is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known exploitation in the wild, though specific in-the-wild campaigns and ransomware use are not documented; EPSS estimates a 3.1% chance of exploitation in the next 30 days.

What to do: Apply the January 2017 Microsoft security update or any later cumulative update for the affected Windows version, prioritizing systems listed in CISA KEV; verify installed updates confirm the GDI privilege escalation fix is present. Systems past extended support (Windows Vista, Windows 7, Windows 8.1, Server 2008/2012 without extended security updates) should receive the applicable ESU patch or be migrated, and restrict local execution of untrusted applications as an interim mitigation.

Affected
Microsoft Windows VistaSP2
Microsoft Windows Server 2008SP2 and R2 SP1 (32-bit/x64/Itanium as shipped)
Microsoft Windows 7SP1 (x86/x64)
Microsoft Windows 8.1x86/x64
Microsoft Windows RT 8.1all
Microsoft Windows Server 2012Gold and R2
Microsoft Windows 101507 (Gold), 1511, and 1607
Microsoft Windows Server 2016Gold (1607-era release)
Estimated exposure
masshundreds of millions of Windows installations worldwide (any unpatched Windows Vista through 10 1607 / Server 2008 through 2016 system) — These versions represent the entire mainstream Windows install base at the time of disclosure (Windows 7/8.1/10 alone accounted for hundreds of millions to billions of devices), and large numbers of legacy systems remain unpatched or out…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0005, CVE-2017-0025, and CVE-2017-0047.

CISA Known Exploited Vulnerability
Affected
Microsoft Graphics Device Interface (GDI)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows vista
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news