Improper input validation in Windows Server - CVE-2017-8686

 

Improper input validation in Windows Server - CVE-2017-8686

Published: September 12, 2017 / Updated: September 12, 2017


Vulnerability identifier: #VU8319
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-8686
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Windows Server

Detailed vulnerability description

The vulnerability allows an adjacent attacker to execute arbitrary code on the target system.

The vulnerability exists in the Windows Server DHCP service due to improper validation of user-supplied input. An adjacent attacker can send specially crafted packets to a DHCP failover server and run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive.

Successful exploitation of this vulnerability may result in system compromise.


How to mitigate CVE-2017-8686

Install updates from vendor's website.

Sources