Vulnerability record · CVE-2017-0263 · published 12 May 2017
CVE-2017-0263: Microsoft Windows Win32k use-after-free privilege escalation
Microsoft · Windows 10 1507
The Win32k kernel-mode drivers in multiple Windows versions contain a use-after-free (CWE-416) that lets a local user escalate privileges by running a crafted application. Because the flaw sits in the kernel, successful exploitation yields full control of the affected host, making it a standard post-compromise escalation step.
Description
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a kernel privilege-escalation flaw with public exploit code and KEV listing, but it requires an existing local foothold and affects largely legacy Windows versions.
What it is
The Win32k kernel-mode drivers in multiple Windows versions contain a use-after-free (CWE-416) that lets a local user escalate privileges by running a crafted application. Because the flaw sits in the kernel, successful exploitation yields full control of the affected host, making it a standard post-compromise escalation step.
Impact
An attacker who already has code execution as a low-privileged local user can gain elevated privileges, typically SYSTEM, on the target machine. That access enables credential theft, disabling of security controls, and lateral movement.
Attack surface
Reached locally: the CVSS vector is AV:L with PR:L and UI:N, so the attacker needs an existing low-privileged account or session on the host and no user interaction. No network or remote vector is described.
Exploitation
It is listed in CISA KEV (added 2022-02-10) and public exploit code exists per Exploit-DB and third-party references; EPSS 30-day probability is about 10% (95th percentile). CISA records no known ransomware campaign use.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-0263 on all affected Windows versions.
- Prioritize patching of Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows Server 2008 SP2/R2 SP1, Windows Server 2012/R2, and Windows Server 2016, plus Windows 10 Gold through 1703.
- Restrict and monitor local interactive logon and RDP access so untrusted users cannot obtain the low-privileged session the exploit requires.
- Where legacy systems cannot be patched, isolate them and limit the accounts and applications permitted to run on them.
Detection
- Alert on unexpected child processes spawning from Office, browsers, or other user-facing applications, which is a common pattern for local privilege-escalation exploits.
- Monitor for processes gaining SYSTEM or high-integrity tokens shortly after a low-privileged process starts.
- Hunt for known public exploit binaries or scripts matching the Exploit-DB 44478 pattern on endpoints.
- Review Windows kernel and Win32k-related crash or bugcheck telemetry for signs of use-after-free exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0263 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "Microsoft Win32k Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 August 2022.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/98258 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038449 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0263 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44478/ | ExploitThird Party AdvisoryVDB Entry |
| https://xiaodaozhi.com/exploit/117.html | ExploitThird Party Advisory |
| http://www.securityfocus.com/bid/98258 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038449 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0263 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44478/ | ExploitThird Party AdvisoryVDB Entry |
| https://xiaodaozhi.com/exploit/117.html | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0263 | US Government Resource |
Track CVE-2017-0263 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0263), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.