Remote Code Execution Vulnerability in Windows IME for Various Microsoft Products
CVE-2017-8591
7.8HIGH
What is CVE-2017-8591?
The vulnerability in the Windows Input Method Editor (IME) occurs due to improper handling of memory objects, which may allow an attacker to execute arbitrary code on the target system. This issue affects multiple versions of Windows, including client and server editions, potentially compromising the integrity and confidentiality of data processed through these systems.
Affected Version(s)
Windows Shell Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016