CVE-2017-8720: High severity Microsoft Windows 10 vulnerability
The Microsoft Windows graphics component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8675.
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this vulnerability?
An attacker needs local access and low privileges on an affected system. No user interaction is required.
What could successful exploitation allow?
Successful exploitation could allow elevation of privilege, with high impact to confidentiality, integrity, and availability.
Which Windows releases are affected?
Affected releases include Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold through version 1703, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016.
Is a fix available?
Yes. A patch is available for this vulnerability.