Vulnerability record · CVE-2017-0101 · published 17 March 2017
CVE-2017-0101: Microsoft Windows Transaction Manager Kernel Driver Privilege Escalation
Microsoft · Windows 7
A memory buffer overflow (CWE-119) in the kernel-mode drivers of the Windows Transaction Manager lets a local user elevate privileges by running a crafted application. Because the flaw sits in kernel-mode code, successful exploitation yields full control of the affected host.
Description
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with documented ransomware use and a public exploit, but exploitation requires local access and user interaction, so it is not remotely wormable.
What it is
A memory buffer overflow (CWE-119) in the kernel-mode drivers of the Windows Transaction Manager lets a local user elevate privileges by running a crafted application. Because the flaw sits in kernel-mode code, successful exploitation yields full control of the affected host.
Impact
An attacker who runs the crafted application gains elevated privileges on the local machine, up to kernel-level code execution. That access can be used to disable security controls, persist, or move laterally.
Attack surface
Reached locally by executing a crafted application on the target host; the CVSS vector (AV:L/PR:N/UI:R) indicates no prior privileges are needed but a user must be induced to run or open the crafted file.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware campaign use, and a public Exploit-DB entry (44479) exists; EPSS 30-day probability is 0.575 (99th percentile).
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-0101 on all affected Windows versions.
- Prioritize patching of unsupported or legacy systems (Vista SP2, Server 2008/R2, Windows 7 SP1, Windows 8.1, RT 8.1, Windows 10 Gold/1511/1607, Server 2016) since they cannot receive other fixes.
- Restrict execution of untrusted applications and attachments via application allowlisting and email/web download controls.
- Run users with standard (non-administrative) privileges to limit the value of a successful local elevation.
- Monitor and retire end-of-life Windows builds that no longer receive security updates.
Detection
- Alert on unexpected elevation of privilege events (e.g., Windows Security event 4672 or process token changes) originating from user-launched applications.
- Hunt for processes spawning from Office, browsers, or email clients that subsequently load kernel-mode or Transaction Manager-related components.
- Monitor for known public exploit artifacts tied to Exploit-DB 44479 and for anomalous writes to kernel driver paths.
- Correlate local privilege-escalation detections with subsequent ransomware-like behavior such as shadow copy deletion or mass file encryption.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0101 to the Known Exploited Vulnerabilities catalog on 15 March 2022 as "Microsoft Windows Transaction Manager Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 April 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/96625 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038013 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0101 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44479/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/96625 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038013 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0101 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44479/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0101 | US Government Resource |
Track CVE-2017-0101 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0101), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.