Windows COM Session Elevation of Privilege Vulnerability in Microsoft Products
CVE-2017-0298

7.3HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
15 June 2017

Summary

A vulnerability exists in the DCOM object of Helppane.exe, which affects various versions of Microsoft Windows, including Windows Server and Windows 10. When configured to run as an interactive user, this flaw allows an authenticated attacker to execute arbitrary code within another user's session. The implications of this vulnerability could enable unauthorized access to sensitive data and system resources, thereby highlighting the importance of applying security updates and monitoring access controls.

Affected Version(s)

Windows COM Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.