ZeroHour

CVE-2017-0005

KEV PoC mass

Local Privilege Escalation Flaw in Microsoft Windows GDI

CISA: Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2017-0005 is an elevation of privilege vulnerability in the Graphics Device Interface (GDI) component of Microsoft Windows, scored 7.8 (High) because a successful exploit compromises confidentiality, integrity, and availability. It is triggered when a local, low-privileged user runs a crafted application that manipulates GDI, causing code to run with elevated privileges. An attacker who already has a foothold on a machine (e.g., via malware or a compromised account) gains higher privileges, enabling full control of the host, persistence, and access to sensitive data. The flaw affects a broad set of Windows releases from Windows Vista SP2 through Windows 10 1607, plus Windows RT 8.1 and Windows Server 2008, 2012, and 2016, so most Windows estates of that era are in scope. Exploitation is confirmed in the wild: Microsoft published detection and mitigation guidance for an actively used exploit in 2017, and CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-05-24; EPSS estimates a ~10.9% probability of exploitation within 30 days (96th percentile).

What to do: Apply Microsoft's security updates for all affected releases per the CISA KEV required action: Windows 10 1507/1511/1607 via cumulative updates, and Windows 7 SP1, 8.1, RT 8.1, Server 2008 SP2/R2 SP1, Server 2012 Gold/R2, and Server 2016 via the corresponding vendor patches. Out-of-support versions such as Vista SP2 or Server 2008 need extended/custom-support updates or an OS upgrade, and Windows 10 devices on 1507/1511/1607 should be moved to a currently serviced build. Because exploitation requires local code execution, restrict untrusted local software, and review Microsoft's MMPC detection guidance referenced for this CVE to hunt for prior exploitation.

Affected
Microsoft Windows VistaSP2
Microsoft Windows 7SP1
Microsoft Windows 8.1all serviced editions at time of disclosure
Microsoft Windows RT 8.18.1
Microsoft Windows 101507 (Gold), 1511, 1607
Microsoft Windows Server 2008SP2 and R2 SP1
Microsoft Windows Server 2012Gold and R2
Microsoft Windows Server 2016
Estimated exposure
masshundreds of millions of Windows PCs and servers across the affected Vista through Windows 10 1607 / Server 2008-2016 releases — The affected releases collectively made up essentially the entire Windows installed base at disclosure (Windows 7 alone ran on hundreds of millions of PCs and Windows 10 1507-1607 on hundreds of millions of devices), and these versions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0025, and CVE-2017-0047.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows vista
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news