
Microsoft Windows Server 2008 SP2およびR2 SP1、Windows 7 SP1、Windows 8.1、Windows Server 2012 GoldおよびR2、Windows RT 8.1、Windows 10 Gold、1511、1607、1703、Windows Server 2016におけるWindows COM Aggregate Marshalerは、攻撃者が特別に細工されたアプリケーションを実行すると特権昇格の脆弱性を許容します。別名「Windows COM Elevation of Privilege Vulnerability」です。このCVE IDはCVE-2017-0214とは異なります。
作成者: Google Security Research
CVE: 2017-0213
EDB-ID: 42020
参考文献: Project-Zero Microsoft Exploit-Database
動画: Youtube
| 製品 | バージョン | 更新プログラム | ビルド | テスト済み |
|---|---|---|---|---|
| Windows 10 | 1511 | 10586 | √ | |
| Windows 10 | 1607 | 14393 | √ | |
| Windows 10 | 1703 | 15063 | √ | |
| Windows 7 | SP1 | √ | ||
| Windows 8.1 | ||||
| Windows RT 8.1 | ||||
| Windows Server 2008 | SP2 | |||
| Windows Server 2008 | R2 | SP1 | ||
| Windows Server 2012 | ||||
| Windows Server 2012 | R2 | |||
| Windows Server 2016 |