CVE-2017-0176
A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 45.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 45.77% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- microsoft/windows server 2003 · microsoft/windows xp
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/98550Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98752Third Party Advisory, VDB Entry
- https://blog.0patch.com/2017/06/a-quick-analysis-of-microsofts.html
- https://blog.fortinet.com/2017/05/11/deep-analysis-of-esteemauditExploit, Third Party Advisory
- https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/Patch, Vendor Advisory
- https://support.microsoft.com/en-us/help/4022747/security-update-for-windows-xp-and-windows-server-2003Patch, Vendor Advisory
- http://www.securityfocus.com/bid/98550Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98752Third Party Advisory, VDB Entry
- https://blog.0patch.com/2017/06/a-quick-analysis-of-microsofts.html
- https://blog.fortinet.com/2017/05/11/deep-analysis-of-esteemauditExploit, Third Party Advisory
- https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/Patch, Vendor Advisory
- https://support.microsoft.com/en-us/help/4022747/security-update-for-windows-xp-and-windows-server-2003Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.