CVE-2017-8584CriticalCVSS 7.5

Broadcom BCM43xx Remote Code Execution Vulnerability

Published
July 11, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A remote code execution vulnerability exists when the Broadcom chipset in HoloLens improperly handles objects in memory. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted WiFi packet. The update addresses the vulnerability by correcting how the Broadcom chipset in HoloLens handles objects in memory.

🎯 Affected products4

  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1607 for x64-based Systems
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)

✅ Remediation

KB4025339 (Security Update)

🔗 References (2)