CVE-2017-8464
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- May 03, 2017
- Published Date
- June 15, 2017
- Last Updated
- February 10, 2025
- Vendor
- Microsoft
- Product
- Windows Shell
- Description
- Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka "LNK Remote Code Execution Vulnerability."
- Tags
- Exploitation
- active
- Technical Impact
- total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-02-10 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2017_8464_lnk_lpe.rb | 2025-04-29 11:01:40 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
cve_2017_8464_lnk_lpe
Type: metasploit • Created: Unknown
cve_2017_8464_lnk_rce
Type: metasploit • Created: Unknown
TieuLong21Prosper/Detect-CVE-2017-8464
Type: github • Created: 2023-11-27 10:28:47 UTC • Stars: 0
tuankiethkt020/Phat-hien-CVE-2017-8464
Type: github • Created: 2023-05-01 14:59:04 UTC • Stars: 0
TrG-1999/DetectPacket-CVE-2017-8464
Type: github • Created: 2022-06-08 01:39:48 UTC • Stars: 2
xssfile/CVE-2017-8464-EXP
Type: github • Created: 2018-04-20 09:01:03 UTC • Stars: 1
doudouhala/CVE-2017-8464-exp-generator
Type: github • Created: 2017-08-07 11:56:11 UTC • Stars: 8
3gstudent/CVE-2017-8464-EXP
Type: github • Created: 2017-08-02 02:14:37 UTC • Stars: 66
Elm0D/CVE-2017-8464
Type: github • Created: 2016-02-24 17:36:29 UTC • Stars: 1
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Proof of Concept Exploit Available
-
Detected by Metasploit