Remote Code Execution Vulnerability in Windows Uniscribe Component by Microsoft
CVE-2017-8692

7.5HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 September 2017

Summary

The vulnerability in the Windows Uniscribe component affects multiple Microsoft operating systems, allowing attackers to execute arbitrary code due to improper memory handling. This flaw exposes systems to potential exploitation, emphasizing the need for timely updates and security patches.

Affected Version(s)

Windows Uniscribe Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016

References

EPSS Score

35% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.