CVE-2017-11829HighCVSS 5.5

Windows Update Delivery Optimization Elevation of Privilege Vulnerability

Published
October 10, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions. An attacker who successfully exploited the vulnerability could overwrite files that require higher privileges than what the attacker already has. To exploit this vulnerability, an attacker would need to log into a system. The attacker could then create a Delivery Optimization job to exploit the vulnerability. The security update addresses the vulnerability by correcting how the Delivery Optimization services enforces permissions.

🎯 Affected products6

  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1703 for 32-bit Systems
  • Windows 10 Version 1703 for x64-based Systems
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)

✅ Remediation

KB4041691 (Security Update) KB4041676 (Security Update)

🔗 References (3)