ZeroHour

CVE-2017-0101

KEV ransomware PoC mass

Local Privilege Escalation in Microsoft Windows Transaction Manager (kernel drivers)

CISA: Microsoft Windows Transaction Manager Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
57%p99
Published
()
KEV added
AI analysis

CVE-2017-0101 is an elevation-of-privilege vulnerability (CWE-119, memory-handling class) in the kernel-mode drivers of the Windows Transaction Manager, affecting Windows Vista SP2 through Windows Server 2016. It is triggered when a local user runs a crafted application on an affected system, allowing them to exploit the flaw and escalate privileges. Successful exploitation yields SYSTEM/administrator-level access on the local machine, which attackers commonly chain as a pre-encryption step in ransomware campaigns. All releases listed in the advisory are affected: Windows Vista SP2, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows 10 RTM/1511/1607, and Windows Server 2008 SP2/R2, Server 2012/R2, and Server 2016 — most of which are now end-of-support. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2022-03-15 with known ransomware use, EPSS assigns a 57.5% probability of exploitation within 30 days (99th percentile), and a public proof-of-concept is available.

What to do: Apply the Microsoft security updates that shipped in the March 2017 Patch Tuesday release for every affected Windows version; for out-of-support editions (Vista, Windows 7, 8.1, Server 2008/2012), either obtain Extended Security Updates, upgrade to a supported OS, or accept documented risk. Because ransomware operators are known to use this flaw to escalate to SYSTEM, prioritize legacy Windows servers and workstations in your estate, verify their patch level, and restrict execution of untrusted local applications.

Affected
Microsoft Windows VistaSP2
Microsoft Windows 7SP1
Microsoft Windows 8.1all supported releases
Microsoft Windows RT 8.1all supported releases
Microsoft Windows 10RTM (Gold), 1511, and 1607
Microsoft Windows Server 2008SP2 and R2
Microsoft Windows Server 2012RTM (Gold) and R2
Microsoft Windows Server 2016all supported releases
Estimated exposure
mass≈100M–1B Windows devices in the affected range (installed bases of the Windows 7/8.1/10-1607 era), though currently exposed unpatched systems are likely in the… — The affected range includes Windows 7 and Windows 10 builds whose installed bases were in the hundreds of millions to roughly a billion devices per public figures, but the patch has been available since the March 2017 Patch Tuesday and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 7, windows server 2008, windows vista
Weakness
CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.