Remote Code Execution Vulnerability in Microsoft JET Database Engine on Various Windows Versions
CVE-2017-0250
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 8 August 2017
Summary
The Microsoft JET Database Engine has a vulnerability that allows remote code execution due to a buffer overflow condition. This occurs in various supported versions of the Windows operating system, making it crucial for users to apply available security updates to mitigate associated risks. Attackers can exploit this vulnerability to execute malicious code on affected systems, which can lead to potential data compromise or system manipulation.
Affected Version(s)
Microsoft JET Database Engine Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016
References
EPSS Score
28% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved