Remote Code Execution Vulnerability in Microsoft JET Database Engine
CVE-2017-8718

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
10 October 2017

Summary

The Microsoft JET Database Engine across several Windows operating systems is susceptible to remote code execution due to improper handling of objects in memory. An attacker can exploit this vulnerability to gain control of an affected system, emphasizing the need for users to apply necessary security updates to mitigate potential risks.

Affected Version(s)

Microsoft JET Database Engine Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016

References

EPSS Score

34% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.