Remote Code Execution Vulnerability in Microsoft JET Database Engine
CVE-2017-8717

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
13 October 2017

Summary

The Microsoft JET Database Engine is susceptible to a vulnerability that could allow attackers to execute arbitrary code on affected systems. This issue arises due to improper handling of objects in memory. Successful exploitation can lead to potential system takeover, compromising confidentiality and integrity. It affects various versions across multiple Windows operating systems, making systems vulnerable to unauthorized access and execution of malicious code.

Affected Version(s)

Microsoft JET Database Engine Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016.

References

EPSS Score

34% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.