Vulnerability record · CVE-2017-0176 · published 22 June 2017
CVE-2017-0176: Microsoft Windows Smart Card Authentication Buffer Overflow in gpkcsp.dll
Microsoft · Windows Server 2003
A buffer overflow exists in the Smart Card authentication code in gpkcsp.dll on Windows XP SP3 and Server 2003 SP2. A remote attacker can execute arbitrary code on a domain-joined machine that has RDP or Terminal Services enabled. The affected platforms are long out of support, so unpatched systems remain exposed.
Description
A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with no authentication or user interaction on unsupported platforms, plus a high EPSS score and an exploit-tagged reference, makes this a serious risk for any remaining XP/2003 systems.
What it is
A buffer overflow exists in the Smart Card authentication code in gpkcsp.dll on Windows XP SP3 and Server 2003 SP2. A remote attacker can execute arbitrary code on a domain-joined machine that has RDP or Terminal Services enabled. The affected platforms are long out of support, so unpatched systems remain exposed.
Impact
Successful exploitation gives the attacker arbitrary code execution on the target computer, typically at the privilege level of the vulnerable service. This can lead to full compromise of the host and, in a domain context, further lateral movement.
Attack surface
The flaw is reached over the network via RDP or Terminal Services on a domain-joined Windows XP or Server 2003 system. No authentication or user interaction is required per the CVSS vector (PR:N, UI:N), though the attack complexity is rated high.
Exploitation
The record is not listed in CISA KEV, but EPSS is 0.45775 (98.7th percentile) and a reference is tagged Exploit, indicating public exploit analysis exists. No ransomware group is documented as using it.
What to do
- Apply the Microsoft security update for Windows XP and Windows Server 2003 (KB4022747) where systems can still be patched.
- Retire or isolate Windows XP and Server 2003 systems; these platforms no longer receive standard security support.
- Disable RDP/Terminal Services on affected hosts that do not require it, and restrict RDP access to trusted management networks.
- Remove affected machines from the Windows domain or limit domain trust where feasible to reduce exposure.
- Monitor for and block exploitation attempts at network boundaries and on RDP endpoints.
Detection
- Monitor RDP/Terminal Services connections to Windows XP and Server 2003 hosts for anomalous or unexpected source addresses.
- Look for crashes or unusual process behavior in services loading gpkcsp.dll on affected systems.
- Review domain-joined legacy hosts for signs of unauthorized code execution or lateral movement following RDP sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-0176 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0176), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.