CVE-2017-0005
KEV PoC massLocal Privilege Escalation Flaw in Microsoft Windows GDI
CISA: Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability
CVE-2017-0005 is an elevation of privilege vulnerability in the Graphics Device Interface (GDI) component of Microsoft Windows, scored 7.8 (High) because a successful exploit compromises confidentiality, integrity, and availability. It is triggered when a local, low-privileged user runs a crafted application that manipulates GDI, causing code to run with elevated privileges. An attacker who already has a foothold on a machine (e.g., via malware or a compromised account) gains higher privileges, enabling full control of the host, persistence, and access to sensitive data. The flaw affects a broad set of Windows releases from Windows Vista SP2 through Windows 10 1607, plus Windows RT 8.1 and Windows Server 2008, 2012, and 2016, so most Windows estates of that era are in scope. Exploitation is confirmed in the wild: Microsoft published detection and mitigation guidance for an actively used exploit in 2017, and CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-05-24; EPSS estimates a ~10.9% probability of exploitation within 30 days (96th percentile).
What to do: Apply Microsoft's security updates for all affected releases per the CISA KEV required action: Windows 10 1507/1511/1607 via cumulative updates, and Windows 7 SP1, 8.1, RT 8.1, Server 2008 SP2/R2 SP1, Server 2012 Gold/R2, and Server 2016 via the corresponding vendor patches. Out-of-support versions such as Vista SP2 or Server 2008 need extended/custom-support updates or an OS upgrade, and Windows 10 devices on 1507/1511/1607 should be moved to a currently serviced build. Because exploitation requires local code execution, restrict untrusted local software, and review Microsoft's MMPC detection guidance referenced for this CVE to hunt for prior exploitation.
| Microsoft Windows Vista | SP2 |
| Microsoft Windows 7 | SP1 |
| Microsoft Windows 8.1 | all serviced editions at time of disclosure |
| Microsoft Windows RT 8.1 | 8.1 |
| Microsoft Windows 10 | 1507 (Gold), 1511, 1607 |
| Microsoft Windows Server 2008 | SP2 and R2 SP1 |
| Microsoft Windows Server 2012 | Gold and R2 |
| Microsoft Windows Server 2016 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0025, and CVE-2017-0047.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows vista
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H