Remote Code Execution Vulnerability in Microsoft JET Database Engine on Various Windows Versions
CVE-2017-0250

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
8 August 2017

Summary

The Microsoft JET Database Engine has a vulnerability that allows remote code execution due to a buffer overflow condition. This occurs in various supported versions of the Windows operating system, making it crucial for users to apply available security updates to mitigate associated risks. Attackers can exploit this vulnerability to execute malicious code on affected systems, which can lead to potential data compromise or system manipulation.

Affected Version(s)

Microsoft JET Database Engine Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016

References

EPSS Score

28% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.