CVE-2017-8464 Information
Description
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1 Windows 7 SP1 Windows 8 Windows 8.1 Windows Server 2012 Gold and R2 Windows RT 8.1 Windows 10 Gold 1511 1607 1703 and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka \LNK Remote Code Execution Vulnerability.\
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/98818 http://www.securitytracker.com/id/1038671 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8464 https://www.exploit-db.com/exploits/42382/ https://www.exploit-db.com/exploits/42429/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: