Improper input validation in Microsoft Windows and Windows Server - CVE-2017-8464
Published: June 13, 2017 / Updated: June 14, 2017
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to an error when processing .LNK files. A remote attacker can create a specially crafted .LNK file and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Note: the vulnerability is being actively exploited in the wild.
Affected software
Windows Server
How to mitigate CVE-2017-8464
Links to Public Exploits and PoC-codes
- Exploit #142 - labs (Vulnerability Labs for security analysis) (March 18, 2020)
- Exploit #143 - CVE-in-Ruby (Exploits written & ported to Ruby - no Metasploit) (March 18, 2020)
- Exploit #1239 - Microsoft Windows - '.LNK' Shortcut File Code Execution (March 18, 2020)
- Exploit #1240 - Microsoft Windows - LNK Shortcut File Code Execution (Metasploit) (March 18, 2020)
- Exploit #1617 - LNK Code Execution Vulnerability (March 18, 2020)
- Exploit #1638 - LNK Code Execution Vulnerability (March 18, 2020)