Rapid7

vulnerability

Microsoft Windows: CVE-2017-8465: Win32k Elevation of Privilege Vulnerability

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 13, 2017
Added
Jun 13, 2017
Modified
Sep 5, 2025

Description

Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to run processes in an elevated context when the Windows kernel improperly handles objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-8468.

Solutions

microsoft-windows-windows_10-1507-kb4022727microsoft-windows-windows_10-1511-kb4022714microsoft-windows-windows_10-1607-kb4022715microsoft-windows-windows_10-1703-kb4022725microsoft-windows-windows_server_2012_r2-kb4022717microsoft-windows-windows_server_2016-1607-kb4022715msft-kb4022717-1d805e7c-215a-4c96-8b39-3829bd2e02d0msft-kb4022717-6abad12a-fc3f-4352-81f7-453e305f13ed
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.