Denial of Service Vulnerability in Windows 10 and Windows Server 2016 Active Directory
CVE-2017-0164

4.4MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 April 2017

What is CVE-2017-0164?

A denial of service vulnerability has been identified in Windows 10 version 1607 and Windows Server 2016 that could be exploited by an authenticated attacker. By sending carefully crafted malicious search queries, the attacker can disrupt the normal functioning of the Active Directory services, potentially leading to service outages and significant disruptions for users. Proper mitigation strategies and updates should be applied to protect affected systems against this vulnerability.

Affected Version(s)

Active Directory Windows 10 1607 and Windows Server 2016

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-0164 : Denial of Service Vulnerability in Windows 10 and Windows Server 2016 Active Directory