Denial of Service Vulnerability in Windows 10 and Windows Server 2016 Active Directory
CVE-2017-0164
4.4MEDIUM
What is CVE-2017-0164?
A denial of service vulnerability has been identified in Windows 10 version 1607 and Windows Server 2016 that could be exploited by an authenticated attacker. By sending carefully crafted malicious search queries, the attacker can disrupt the normal functioning of the Active Directory services, potentially leading to service outages and significant disruptions for users. Proper mitigation strategies and updates should be applied to protect affected systems against this vulnerability.
Affected Version(s)
Active Directory Windows 10 1607 and Windows Server 2016
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved