peter bassill · operator
$ cve CVE-2017-0100 JSON

CVE-2017-0100 EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 5% (pctl 92)

Patch early

A public exploit exists.

Description

A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows HelpPane Elevation of Privilege Vulnerability."

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS4.96% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2017-03-17
Last modified2026-06-17

Affected (7)

VendorProduct
microsoftwindows 10
microsoftwindows 7
microsoftwindows 8.1
microsoftwindows rt 8.1
microsoftwindows server 2008
microsoftwindows server 2012
microsoftwindows server 2016

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD