Denial of service in Windows Subsystem for Linux

Published: 2017-10-10 23:59:57
Severity Low
Patch available YES
Number of vulnerabilities 1
CVSSv2 3.8 (AV:L/AC:L/Au:N/C:N/I:N/A:C/E:POC/RL:OF/RC:C)
CVSSv3 5.8 [CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C]
CVE ID CVE-2017-8703
CWE ID CWE-264
Exploitation vector Local
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software Windows
Vulnerable software versions Windows 10
Vendor URL Microsoft
Advisory type Public

Security Advisory

1) Denial of service

Description

The vulnerability allows a local attacker to perform a DoS attack.

The vulnerability exists due to an error when Windows Subsystem for Linux improperly handles objects in memory. A local attacker can run a specially crafted application and cause the system to crash.

Successful exploitation of the vulnerability results in denial of service.

Remediation

Install updates from vendor's website.

External links

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8703

Back to List