CVE-2017-0101
KEV ransomware PoC massLocal Privilege Escalation in Microsoft Windows Transaction Manager (kernel drivers)
CISA: Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
CVE-2017-0101 is an elevation-of-privilege vulnerability (CWE-119, memory-handling class) in the kernel-mode drivers of the Windows Transaction Manager, affecting Windows Vista SP2 through Windows Server 2016. It is triggered when a local user runs a crafted application on an affected system, allowing them to exploit the flaw and escalate privileges. Successful exploitation yields SYSTEM/administrator-level access on the local machine, which attackers commonly chain as a pre-encryption step in ransomware campaigns. All releases listed in the advisory are affected: Windows Vista SP2, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows 10 RTM/1511/1607, and Windows Server 2008 SP2/R2, Server 2012/R2, and Server 2016 — most of which are now end-of-support. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2022-03-15 with known ransomware use, EPSS assigns a 57.5% probability of exploitation within 30 days (99th percentile), and a public proof-of-concept is available.
What to do: Apply the Microsoft security updates that shipped in the March 2017 Patch Tuesday release for every affected Windows version; for out-of-support editions (Vista, Windows 7, 8.1, Server 2008/2012), either obtain Extended Security Updates, upgrade to a supported OS, or accept documented risk. Because ransomware operators are known to use this flaw to escalate to SYSTEM, prioritize legacy Windows servers and workstations in your estate, verify their patch level, and restrict execution of untrusted local applications.
| Microsoft Windows Vista | SP2 |
| Microsoft Windows 7 | SP1 |
| Microsoft Windows 8.1 | all supported releases |
| Microsoft Windows RT 8.1 | all supported releases |
| Microsoft Windows 10 | RTM (Gold), 1511, and 1607 |
| Microsoft Windows Server 2008 | SP2 and R2 |
| Microsoft Windows Server 2012 | RTM (Gold) and R2 |
| Microsoft Windows Server 2016 | all supported releases |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 7, windows server 2008, windows vista
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.