LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0213: Microsoft Windows Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0213 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

CVE-2017-0213 is a privilege-escalation vulnerability in Microsoft Windows that involves the COM Aggregate Marshaler. An attacker who can already run code on a system may use a specially crafted application to gain higher privileges. This matters because elevated access lets an attacker move laterally, disable defenses, or deploy further payloads. Public reporting associates this vulnerability with known ransomware use, so unpatched systems remain a practical risk for defenders.

How it works

The flaw sits in the Windows Component Object Model (COM) Aggregate Marshaler. COM handles object communication and marshaling across process boundaries. When the Aggregate Marshaler processes certain requests incorrectly, a local attacker can abuse it to escalate privileges.

In practice, the attacker must already be able to execute a specially crafted application on the target. That application interacts with the vulnerable COM component in a way that causes the system to grant higher privileges than the attacker’s original token allows. Exact exploit mechanics and any version-specific triggers are not detailed in the supplied summary; confirm behavior and affected builds against the vendor advisory. Because the weakness is local privilege escalation, it is typically chained after an initial foothold rather than used for remote code execution by itself.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. COM is a core platform component present on desktop and server editions, so inventory should cover workstations, member servers, and domain controllers that have not received the relevant security update.

How to remediate

Patch first. Apply the Microsoft updates that remediate CVE-2017-0213 exactly as directed in the vendor advisory and the CISA-required action to apply updates per vendor instructions. Use your standard patch-deployment process (WSUS, ConfigMgr, Intune, or equivalent), verify installation, and reboot where required.

If you can't patch immediately

Reduce the chance that an attacker can reach and abuse the vulnerable component until the update can be installed.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used to deepen access after an initial breach and have been linked to ransomware. If you suspect compromise, isolate affected hosts, preserve forensic evidence, rotate credentials, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents and take appropriate follow-up steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities