
Microsoft Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016의 Windows COM Aggregate Marshaler에서 공격자가 특수 제작된 응용 프로그램을 실행할 때 권한 상승 취약점이 발생합니다. 일명 "Windows COM Elevation of Privilege Vulnerability"입니다. 이 CVE ID는 CVE-2017-0214와는 별개입니다.
작성자: Google Security Research
CVE: 2017-0213
EDB-ID: 42020
참고 자료: Project-Zero Microsoft Exploit-Database
동영상: Youtube
| 제품 | 버전 | 업데이트 | 빌드 | 테스트 완료 |
|---|---|---|---|---|
| Windows 10 | 1511 | 10586 | √ | |
| Windows 10 | 1607 | 14393 | √ | |
| Windows 10 | 1703 | 15063 | √ | |
| Windows 7 | SP1 | √ | ||
| Windows 8.1 | ||||
| Windows RT 8.1 | ||||
| Windows Server 2008 | SP2 | |||
| Windows Server 2008 | R2 | SP1 | ||
| Windows Server 2012 | ||||
| Windows Server 2012 | R2 | |||
| Windows Server 2016 |