Vulnerability Manager Plus
Free Trial
  • Overview
  • Features
  • Demo
  • Documents
  • Get Quote
  • Support
Home
 

Windows DNS Query Information Disclosure Vulnerability for Windows Vista for x64-based Systems (KB3217587)

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Base Score
10.0
MODERATE
Vector
I:C/AV:N/Au:N/AC:L/A:C/C:C
EPSS Score
Exploitation Probability
34.683%

CVE Information

Source CVE
CVE-2017-0100

Associated CVE
CVE-2017-0100
CVE-2017-0104
CVE-2017-0039
CVE-2017-0057
CVE-2017-0007

Patch Details

Patch associated with this vulnerability is supported by ManageEngine.

Patch ID
22078

Patch Description
Security Update for Windows Vista for x64-based Systems (KB3217587)

References

http://blog.inspired-sec.com/archive/2017/03/17/COM-Moniker-Privesc.html
http://www.securityfocus.com/bid/96018
http://www.securityfocus.com/bid/96024
http://www.securityfocus.com/bid/96695
http://www.securityfocus.com/bid/96697
http://www.securityfocus.com/bid/96700
http://www.securitytracker.com/id/1038001
https://bugs.chromium.org/p/project-zero/issues/detail?id=1021
https://enigma0x3.net/2017/04/03/defeating-device-guard-a-look-into-cve-2017-0007/
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0007
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0039
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0057
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0100
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0104
https://www.exploit-db.com/exploits/41607/

Details

CWE ID
CWE-287
CWE Type
Gain privileges
Vulnerability ID
15257
Published
2017-03-17
Updated
2026-02-27

Vulnerability Intelligence

Evaluate vulnerabilities across managed endpoints with enriched threat intelligence and risk context such as:

Risk Score
Emerging Risk Catalog
CERT Advisories
Risk Indicators