CVE-2017-8591 Information
Feb 14, 2021
cve
Description
Windows Input Method Editor (IME) in Windows 8.1 Windows Server 2012 Gold and R2 Windows RT 8.1 Windows 10 Gold 1511 1607 and 1703 and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory aka \Windows IME Remote Code Execution Vulnerability.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/99430 http://www.securitytracker.com/id/1039097 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8591
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: