CVE-2017-8686
9.8
CRITICAL · CVSS 3.0 · EPSS 27.5% (pctl 98)
Patch early
EPSS 27.5% — above the 10% action threshold.
Description
The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 27.5% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-09-13 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows server 2012 |
| microsoft | windows server 2016 |
References
- http://www.securityfocus.com/bid/100730
- http://www.securitytracker.com/id/1039337
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8686
- http://www.securityfocus.com/bid/100730
- http://www.securitytracker.com/id/1039337
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8686
→ the Explorer · watch your stack · NVD