SB2017091227 - Arbitrary code execution in Windows Server DHCP



SB2017091227 - Arbitrary code execution in Windows Server DHCP

Published: September 12, 2017

Security Bulletin ID SB2017091227
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper input validation (CVE-ID: CVE-2017-8686)

The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.

The vulnerability exists in the Windows Server DHCP service due to improper validation of user-supplied input. An adjacent attacker can send specially crafted packets to a DHCP failover server and run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive.

Successful exploitation of this vulnerability may result in system compromise.


Remediation

Install update from vendor's website.