#VU8781 Privilege escalation in Windows and Windows Server - CVE-2017-11783

 

#VU8781 Privilege escalation in Windows and Windows Server - CVE-2017-11783

Published: October 10, 2017 / Updated: June 17, 2021


Vulnerability identifier: #VU8781
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2017-11783
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: Public exploit is available
Vulnerable software:
Windows
Windows Server
Software vendor:
Microsoft

Description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to an error when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). A local attacker can run a specially crafted application and execute arbitrary code with SYSTEM privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links