Severity | High |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE ID | CVE-2017-11885 |
CVSSv3 |
8.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C] |
CWE ID | CWE-119 |
Exploitation vector | Network |
Public exploit | Not available |
Vulnerable software |
Windows Windows Server |
Vulnerable software versions |
Windows 8.1 Windows 7 Windows 10 Windows RT 8.1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2008 Windows Server 2008 R2 Windows Server 2016 |
Vendor URL | Microsoft |
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when processing RPC requests in Routing and Remote Access (RRAS) service. A remote unauthenticated attacker can send a specially crafted RPC request to the vulnerable server and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
RemediationInstall updates from vendor's website.
External linkshttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11885