CVE-2017-0213
KEV ransomware PoC massLocal Privilege Escalation in Microsoft Windows COM Aggregate Marshaler
CISA: Microsoft Windows Privilege Escalation Vulnerability
CVE-2017-0213 is an elevation of privilege flaw in the Windows COM Aggregate Marshaler affecting Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 (1507/1511/1607/1703), and Windows Server 2008 SP2/R2 SP1 through Server 2016. It is triggered when a local, low-privileged user runs a specially crafted application that abuses COM aggregate marshaling; there is no remote or network attack vector, and user interaction is required. Successful exploitation lets the attacker execute code with elevated privileges (up to SYSTEM) on the local machine, typically as a step toward full host compromise, and CISA notes known ransomware use. All users of the listed Windows client and server versions are affected; the flaw was fixed in Microsoft's May 2017 Patch Tuesday. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28, ransomware use known), a public PoC exists (Exploit-DB 42020), and EPSS assigns a top-percentile 84.1% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's May 2017 security update for this COM elevation-of-privilege flaw, or later monthly/cumulative rollups, on every affected Windows 7/8.1/RT 8.1/10 and Server 2008/2012/2016 system, prioritizing hosts where untrusted users can run applications (terminal/RDS servers, shared workstations, VDI). Inventory installed updates to confirm patching, and give legacy Windows 7/Server 2008/2012 estates special attention because this bug has documented ransomware-linked exploitation; if compromise is suspected, hunt for local privilege-escalation artifacts and follow the KEV required action of applying vendor updates.
| Microsoft Windows 7 | SP1 |
| Microsoft Windows 8.1 | as listed (no service-pack detail in source data) |
| Microsoft Windows RT 8.1 | as listed (no version detail in source data) |
| Microsoft Windows 10 | 1507 (Gold), 1511, 1607, 1703 |
| Microsoft Windows Server 2008 | SP2 and R2 SP1 |
| Microsoft Windows Server 2012 | Gold and R2 |
| Microsoft Windows Server 2016 | as listed (no version detail in source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 10 1607, windows 10 1703, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H