
Windows COM Aggregate Marshaler 存在于 Microsoft Windows Server 2008 SP2 和 R2 SP1、Windows 7 SP1、Windows 8.1、Windows Server 2012 Gold 和 R2、Windows RT 8.1、Windows 10 Gold、1511、1607 和 1703 以及 Windows Server 2016 中。当攻击者运行特制的应用程序时,存在一个权限提升漏洞,也称为“Windows COM Elevation of Privilege Vulnerability”。此 CVE ID 与 CVE-2017-0214 不同。
作者: Google 安全研究团队
CVE: 2017-0213
EDB-ID: 42020
参考: Project-Zero Microsoft Exploit-Database
视频: Youtube
| 产品 | 版本 | 更新 | 内部版本 | 已测试 |
|---|---|---|---|---|
| Windows 10 | 1511 | 10586 | √ | |
| Windows 10 | 1607 | 14393 | √ | |
| Windows 10 | 1703 | 15063 | √ | |
| Windows 7 | SP1 | √ | ||
| Windows 8.1 | ||||
| Windows RT 8.1 | ||||
| Windows Server 2008 | SP2 | |||
| Windows Server 2008 | R2 | SP1 | ||
| Windows Server 2012 | ||||
| Windows Server 2012 | R2 | |||
| Windows Server 2016 |