LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0101: Microsoft Windows Transaction Manager Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0101 to its Known Exploited Vulnerabilities catalog on Mar 15, 2022, with a federal patch deadline of Apr 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.

CVE-2017-0101 is a privilege escalation vulnerability in Microsoft Windows affecting the Windows Transaction Manager. When that component improperly handles objects in memory, an attacker who already has a foothold on a system can elevate privileges. It matters because privilege escalation is a common step after initial access, and this issue has been associated with ransomware activity. Confirm exact product applicability and fixed builds against the vendor advisory.

How it works

The underlying weakness is CWE-119: improper restriction of operations within the bounds of a memory buffer (or related mishandling of objects in memory). In this case, the Windows Transaction Manager does not correctly manage certain objects in memory. An attacker who can run code in a less-privileged context may trigger the flawed handling to corrupt or misuse memory structures, resulting in elevated privileges on the local system.

Public detail on precise exploit mechanics is limited. Defenders should treat this as a local elevation-of-privilege issue in the Transaction Manager path rather than a remote code execution flaw by itself. Successful abuse typically requires the ability to execute code or influence Transaction Manager operations on the target host. Specifics of trigger conditions and memory objects must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

This vulnerability affects Microsoft Windows systems that include the Windows Transaction Manager component. That component is part of the core operating system on many Windows client and server installations, so inventory should cover workstations, member servers, and domain controllers unless the vendor advisory explicitly excludes a SKU or role.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA’s required action. Deploy through your normal Windows Update, WSUS, Microsoft Endpoint Configuration Manager, or equivalent channel, then verify installation via build number or update history.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk. Use them only as a bridge until the vendor update is applied.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used in ransomware and broader intrusion chains. If you have evidence of exploitation or unpatched exposure on sensitive hosts, follow your incident-response process: isolate affected systems, preserve logs and memory where appropriate, rotate credentials that may have been accessible, and assess whether attackers moved laterally or accessed data. You can run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-119
Added to CISA KEVMar 15, 2022
Federal patch deadlineApr 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities