CVE-2017-8461

Description

Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute code on a targeted RPC server which has Routing and Remote Access enabled via a specially crafted application, aka Windows RPC Remote Code Execution Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
8.421

Associated Vulnerability

VulnerabilityOS Platform
Windows Search Remote Code Execution Vulnerability for Windows Vista for x64-based Systems (KB4024402)Windows
Windows Search Remote Code Execution Vulnerability for x64-based Systems (KB4024402)Windows
Windows Search Remote Code Execution Vulnerability for Windows Vista (KB4024402)Windows
Windows Search Remote Code Execution Vulnerability windows search vulnerabilities in Windows Server 2008 (KB4024402)Windows
Windows Search Remote Code Execution Vulnerability for Windows Server 2003 for x64-based Systems (KB4024402)Windows
Windows Search Remote Code Execution Vulnerability for Windows XP SP2 for x64-based Systems (KB4024402)Windows
Windows Search Remote Code Execution Vulnerability for Windows Server 2003 (KB4024402)Windows
Windows Search Remote Code Execution Vulnerability for Windows XP SP3 (KB4024402)Windows
Win32k Information Disclosure Vulnerability for the windows win32k information disclosure vulnerability in Windows Server 2008 for x64-based Systems (KB4019204)Windows
Win32k Information Disclosure Vulnerability for the windows win32k information disclosure vulnerability in Windows Server 2008 (KB4019204)Windows
Microsoft Browser Spoofing Vulnerability for Internet Explorer 10 for Windows Server 2012 (KB4018271) - CumulativeWindows
Microsoft Browser Spoofing Vulnerability for Internet Explorer 11 for Windows Server 2012 R2 (KB4018271) - CumulativeWindows
Microsoft Browser Spoofing Vulnerability for Internet Explorer 11 for Windows 8.1 (KB4018271) - CumulativeWindows
Microsoft Browser Spoofing Vulnerability for Internet Explorer 11 for Windows Server 2008 R2 for x64-based Systems (KB4018271) - CumulativeWindows
Microsoft Browser Spoofing Vulnerability for Internet Explorer 11 for Windows 7 (KB4018271) - CumulativeWindows
Microsoft Browser Spoofing Vulnerability for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB4018271) - CumulativeWindows
Microsoft Browser Spoofing Vulnerability for Internet Explorer 9 for Windows Server 2008 (KB4018271) - CumulativeWindows
Windows SMB Denial of Service Vulnerability for the windows smb information disclosure vulnerability in Windows Server 2008 (KB4018466)Windows
Windows SMB Denial of Service Vulnerability for the windows smb information disclosure vulnerability in Windows Server 2008 for x64-based Systems (KB4018466)Windows
CVE-2017-8461NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-22564Security Update for Windows Vista for x64-based Systems (KB4024402)
PATCH-22565Security Update for Windows Server 2008 for x64-based Systems (KB4024402)
PATCH-22560Security Update for Windows Vista (KB4024402)
PATCH-22561Security Update for Windows Server 2008 (KB4024402)
PATCH-22563Security Update for Windows Server 2003 for x64-based Systems (KB4024402)
PATCH-22562Security Update for Windows XP SP2 for x64-based Systems (KB4024402)
PATCH-22559Security Update for Windows Server 2003 (KB4024402)
PATCH-22558Security Update for Windows XP SP3 (KB4024402)
PATCH-22536Security Update for Windows Server 2008 for x64-based Systems (KB4019204)
PATCH-22535Security Update for Windows Server 2008 (KB4019204)
PATCH-22470Cumulative Security Update for Internet Explorer 10 for Windows Server 2012 (KB4018271)
PATCH-22472Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB4018271)
PATCH-22466Cumulative Security Update for Internet Explorer 11 for Windows 8.1 (KB4018271)
PATCH-22469Cumulative Security Update for Internet Explorer 11 for Windows Server 2008 R2 for x64-based Systems (KB4018271)
PATCH-22465Cumulative Security Update for Internet Explorer 11 for Windows 7 (KB4018271)
PATCH-22467Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 x64 Edition (KB4018271)
PATCH-22464Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 (KB4018271)
PATCH-22523Security Update for Windows Server 2008 (KB4018466)
PATCH-22524Security Update for Windows Server 2008 for x64-based Systems (KB4018466)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234