VulnerabilityModified
CVE-2017-11829
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
MEDIUM 5.5EPSS 3.78%
Does this matter?
Lower severity and a low EPSS score (3.78%). Track it; it rarely justifies an emergency change on its own.
Description
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 3.78% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-552
- Affected
- microsoft/windows 10 · microsoft/windows server 2016
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/101213Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039526Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11829Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101213Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039526Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11829Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.