ZeroHour

CVE-2017-0263

KEV PoC ×2mass

Win32k Use-After-Free Local Privilege Escalation in Windows 7 through Server 2016

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2017-0263 is a use-after-free flaw (CWE-416) in the Windows kernel-mode drivers (Win32k) that allows a locally authenticated user to elevate privileges. It is triggered by running a specially crafted application that mishandles kernel memory on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607/1703, and Windows Server 2008 SP2/R2 SP1, Server 2012 Gold/R2, and Server 2016. Successful exploitation yields kernel-level privileges, effectively giving an attacker full control of the host and making it a common link in chained attacks alongside other bugs; related 2017 reporting associated the flaw with Sofacy (APT28) activity. Any unpatched Windows installation of the affected releases is affected, including long-lived legacy desktops and servers. The flaw is confirmed exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-02-10) — with two public PoC/exploit references and a ~10% EPSS probability of exploitation in the next 30 days (95th percentile).

What to do: Apply Microsoft security updates per vendor instructions - this Win32k bug was fixed in the April 2017 Patch Tuesday release - prioritizing hosts where untrusted or low-privileged users can execute code (terminal/VDI servers, shared workstations, jump hosts). Windows 7/8.1 and Server 2008/2012 are past end of extended support, so use Extended Security Updates or migrate where patching in place is not possible. Verify installed builds against the affected version list above and close out the CISA KEV remediation requirement promptly.

Affected
microsoft windows 101507 (Gold), 1511, 1607, 1703
microsoft windows 7SP1
microsoft windows 8.1all versions at disclosure
microsoft windows rt 8.1all versions at disclosure
microsoft windows server 2008SP2 and R2 SP1
microsoft windows server 2012Gold and R2
microsoft windows server 2016all versions at disclosure
Estimated exposure
masshundreds of millions of devices (all unpatched Windows 7/8.1/RT 8.1 and Windows 10 1507-1703 PCs, plus the dominant Windows Server releases of that era) — Estimated from OS market share at disclosure: Windows 7 alone held roughly half of the global Windows installed base (hundreds of millions of PCs) and the affected Windows Server releases were the prevailing server versions of the period,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 10 1607, windows 10 1703, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news