ZeroHour

CVE-2017-0213

KEV ransomware PoC mass

Local Privilege Escalation in Microsoft Windows COM Aggregate Marshaler

CISA: Microsoft Windows Privilege Escalation Vulnerability

CVSS 3.1
7.3 high
EPSS
84%p100
Published
()
KEV added
AI analysis

CVE-2017-0213 is an elevation of privilege flaw in the Windows COM Aggregate Marshaler affecting Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 (1507/1511/1607/1703), and Windows Server 2008 SP2/R2 SP1 through Server 2016. It is triggered when a local, low-privileged user runs a specially crafted application that abuses COM aggregate marshaling; there is no remote or network attack vector, and user interaction is required. Successful exploitation lets the attacker execute code with elevated privileges (up to SYSTEM) on the local machine, typically as a step toward full host compromise, and CISA notes known ransomware use. All users of the listed Windows client and server versions are affected; the flaw was fixed in Microsoft's May 2017 Patch Tuesday. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28, ransomware use known), a public PoC exists (Exploit-DB 42020), and EPSS assigns a top-percentile 84.1% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's May 2017 security update for this COM elevation-of-privilege flaw, or later monthly/cumulative rollups, on every affected Windows 7/8.1/RT 8.1/10 and Server 2008/2012/2016 system, prioritizing hosts where untrusted users can run applications (terminal/RDS servers, shared workstations, VDI). Inventory installed updates to confirm patching, and give legacy Windows 7/Server 2008/2012 estates special attention because this bug has documented ransomware-linked exploitation; if compromise is suspected, hunt for local privilege-escalation artifacts and follow the KEV required action of applying vendor updates.

Affected
Microsoft Windows 7SP1
Microsoft Windows 8.1as listed (no service-pack detail in source data)
Microsoft Windows RT 8.1as listed (no version detail in source data)
Microsoft Windows 101507 (Gold), 1511, 1607, 1703
Microsoft Windows Server 2008SP2 and R2 SP1
Microsoft Windows Server 2012Gold and R2
Microsoft Windows Server 2016as listed (no version detail in source data)
Estimated exposure
masshundreds of millions of Windows systems (Windows 7/8.1/10-era desktop and server installed base) — The affected range spans essentially the entire Windows client and server installed base of the era (Windows 7 alone ran on hundreds of millions of PCs), so total exposure is on the order of 10^8 installations, though many of these…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 10 1607, windows 10 1703, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news