CVE-2017-0001
KEVmassLocal Privilege Escalation in Microsoft Windows GDI
CISA: Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
CVE-2017-0001 is a privilege escalation flaw in the Windows Graphics Device Interface (GDI) that affects Windows Vista through Windows 10 (1507, 1511, 1607) and Windows Server 2008 through 2016. It is triggered by a local attacker who runs a crafted application on an affected system, requiring only low local privileges and no user interaction. Successful exploitation grants the attacker elevated privileges, with high impact on confidentiality, integrity and availability, effectively giving full control of the host. Any organization running unpatched copies of these Windows client or server versions is affected. The flaw is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known exploitation in the wild, though specific in-the-wild campaigns and ransomware use are not documented; EPSS estimates a 3.1% chance of exploitation in the next 30 days.
What to do: Apply the January 2017 Microsoft security update or any later cumulative update for the affected Windows version, prioritizing systems listed in CISA KEV; verify installed updates confirm the GDI privilege escalation fix is present. Systems past extended support (Windows Vista, Windows 7, Windows 8.1, Server 2008/2012 without extended security updates) should receive the applicable ESU patch or be migrated, and restrict local execution of untrusted applications as an interim mitigation.
| Microsoft Windows Vista | SP2 |
| Microsoft Windows Server 2008 | SP2 and R2 SP1 (32-bit/x64/Itanium as shipped) |
| Microsoft Windows 7 | SP1 (x86/x64) |
| Microsoft Windows 8.1 | x86/x64 |
| Microsoft Windows RT 8.1 | all |
| Microsoft Windows Server 2012 | Gold and R2 |
| Microsoft Windows 10 | 1507 (Gold), 1511, and 1607 |
| Microsoft Windows Server 2016 | Gold (1607-era release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0005, CVE-2017-0025, and CVE-2017-0047.
- Affected
- Microsoft Graphics Device Interface (GDI)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H