CVE-2017-11818: Medium severity Microsoft Windows 10 vulnerability
The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level check, aka "Windows Storage Security Feature Bypass Vulnerability".
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs local access to the affected system and low-level privileges. The CVSS vector indicates no user interaction is required, but exploitation has high attack complexity.
Which Windows releases are identified as affected?
Affected releases include Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016.
What is the potential impact if exploitation succeeds?
Successful exploitation bypasses an integrity-level security check in the Windows Storage component. The listed impact includes limited effects on confidentiality, integrity, and availability.
What should organizations do to remediate this vulnerability?
Apply the available patch for the affected Windows release.