Remote Code Execution Vulnerability in Microsoft Windows Products
CVE-2017-0084
8.8HIGH
What is CVE-2017-0084?
The vulnerability in Uniscribe allows remote attackers to execute arbitrary code on affected Microsoft Windows products by crafting malicious web content. This exploitation can lead to unauthorized access, system takeover, and potential data breaches, making it critical for users of these Windows versions to apply patches and enhance their security measures to mitigate risks.
Affected Version(s)
Windows Uniscribe Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016
References
EPSS Score
26% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved