CVE-2017-0174
medium
CVSS v3
6.5
CVSS v2
6.1
VIR risk
6.5
Description
Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles NetBIOS packets, aka "Windows NetBIOS Denial of Service Vulnerability".
Predictions
Exploit likelihood
65%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@microsoft.com — https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0174
Mitigation details
Source: Microsoft Security Response Center · View original ↗ · proprietary-no-redistribution
Full prose not cached — VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.
Affected
| Vendor | Product | Version |
|---|---|---|
| microsoft | Windows 7 for 32-bit Systems Service Pack 1 | |
| microsoft | Windows 7 for x64-based Systems Service Pack 1 | |
| microsoft | Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | |
| microsoft | Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 | |
| microsoft | Windows Server 2008 R2 for x64-based Systems Service Pack 1 | |
| microsoft | Microsoft SharePoint Server 2010 Service Pack 2 | |
| microsoft | Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | |
| microsoft | Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2 | |
| microsoft | Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2 | |
| microsoft | Windows Server 2012 | |
| microsoft | Windows Server 2012 (Server Core installation) | |
| microsoft | Adobe Flash Player on Windows Server 2012 | |
| microsoft | Adobe Flash Player on Windows 8.1 for 32-bit systems | |
| microsoft | Adobe Flash Player on Windows 8.1 for x64-based systems | |
| microsoft | Adobe Flash Player on Windows Server 2012 R2 | |
| microsoft | Adobe Flash Player on Windows RT 8.1 | |
| microsoft | Adobe Flash Player on Windows 10 for 32-bit Systems | |
| microsoft | Adobe Flash Player on Windows 10 for x64-based Systems | |
| microsoft | Adobe Flash Player on Windows 10 Version 1511 for x64-based Systems | |
| microsoft | Adobe Flash Player on Windows 10 Version 1511 for 32-bit Systems | |
| microsoft | Adobe Flash Player on Windows Server 2016 | |
| microsoft | Adobe Flash Player on Windows 10 Version 1607 for 32-bit Systems | |
| microsoft | Adobe Flash Player on Windows 10 Version 1607 for x64-based Systems | |
| microsoft | Adobe Flash Player on Windows 10 Version 1703 for 32-bit Systems | |
| microsoft | Adobe Flash Player on Windows 10 Version 1703 for x64-based Systems | |
| microsoft | Windows 8.1 for 32-bit systems | |
| microsoft | Windows 8.1 for x64-based systems | |
| microsoft | Windows Server 2012 R2 | |
| microsoft | Windows RT 8.1 | |
| microsoft | Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1 | |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| windows | - | affected | |
| windows | 1511 | affected | |
| windows | 1607 | affected | |
| windows | 1703 | affected | |
| windows | affected | | |
| windows | r2 | affected | |
References
- http://www.securityfocus.com/bid/100038
- http://www.securitytracker.com/id/1039109
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0174
- http://www.securityfocus.com/bid/100038
- http://www.securitytracker.com/id/1039109
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0174
Verify integrity in audit chain (admin only). AS-IS.