← Vulnerability feed

Vulnerability record · CVE-2017-0176 · published 22 June 2017

CVE-2017-0176: Microsoft Windows Smart Card Authentication Buffer Overflow in gpkcsp.dll

Microsoft · Windows Server 2003

A buffer overflow exists in the Smart Card authentication code in gpkcsp.dll on Windows XP SP3 and Server 2003 SP2. A remote attacker can execute arbitrary code on a domain-joined machine that has RDP or Terminal Services enabled. The affected platforms are long out of support, so unpatched systems remain exposed.

8.1 CVSS 3.0 High EPSS 46% · top 1.2% CWE-120 · Classic buffer overflow
8.1CVSS 3.0 base score, v2 9.3
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote code execution with no authentication or user interaction on unsupported platforms, plus a high EPSS score and an exploit-tagged reference, makes this a serious risk for any remaining XP/2003 systems.

What it is

A buffer overflow exists in the Smart Card authentication code in gpkcsp.dll on Windows XP SP3 and Server 2003 SP2. A remote attacker can execute arbitrary code on a domain-joined machine that has RDP or Terminal Services enabled. The affected platforms are long out of support, so unpatched systems remain exposed.

Impact

Successful exploitation gives the attacker arbitrary code execution on the target computer, typically at the privilege level of the vulnerable service. This can lead to full compromise of the host and, in a domain context, further lateral movement.

Attack surface

The flaw is reached over the network via RDP or Terminal Services on a domain-joined Windows XP or Server 2003 system. No authentication or user interaction is required per the CVSS vector (PR:N, UI:N), though the attack complexity is rated high.

Exploitation

The record is not listed in CISA KEV, but EPSS is 0.45775 (98.7th percentile) and a reference is tagged Exploit, indicating public exploit analysis exists. No ransomware group is documented as using it.

What to do

  • Apply the Microsoft security update for Windows XP and Windows Server 2003 (KB4022747) where systems can still be patched.
  • Retire or isolate Windows XP and Server 2003 systems; these platforms no longer receive standard security support.
  • Disable RDP/Terminal Services on affected hosts that do not require it, and restrict RDP access to trusted management networks.
  • Remove affected machines from the Windows domain or limit domain trust where feasible to reduce exposure.
  • Monitor for and block exploitation attempts at network boundaries and on RDP endpoints.

Detection

  • Monitor RDP/Terminal Services connections to Windows XP and Server 2003 hosts for anomalous or unexpected source addresses.
  • Look for crashes or unusual process behavior in services loading gpkcsp.dll on affected systems.
  • Review domain-joined legacy hosts for signs of unauthorized code execution or lateral movement following RDP sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-0176 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2015-2360Microsoft Windows win32k.sys memory corruption privilege escalationwin32k.sys in the Windows kernel-mode drivers mishandles memory, allowing a local user to corrupt memory through a crafted application. The flaw is a…KEVEPSS 15%analysed8.8CVE-2014-6324Microsoft Windows Kerberos KDC privilege escalation via forged ticket signatureThe Kerberos Key Distribution Center (KDC) in multiple Windows client and server versions fails to properly validate the signature (checksum) in a ti…KEVEPSS 87%analysed8.8CVE-2014-6332Windows OLE Automation SafeArrayDimen array redimensioning remote code executionOleAut32.dll in Windows OLE mishandles a size value in the SafeArrayDimen function, allowing an array-redimensioning attempt to corrupt memory. A cra…KEVEPSS 95%analysed8.8CVE-2014-4148Windows win32k.sys TrueType font parsing remote code executionA code injection flaw in the win32k.sys kernel-mode driver lets a crafted TrueType font trigger arbitrary code execution. Because font parsing sits i…KEVEPSS 60%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed8.8CVE-2011-3402Microsoft Windows TrueType Font Parsing Remote Code ExecutionThe TrueType font parsing engine in win32k.sys on multiple Windows versions fails to properly handle crafted font data, allowing remote code executio…KEVEPSS 78%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2017-0176), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.