CVE-2017-11885 Details
Description
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow a remote code execution vulnerability due to the way the Routing and Remote Access service handles requests, aka "Windows RRAS Service Remote Code Execution Vulnerability".
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11885 | CVE | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44616/ | CVE | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102055 | CVE | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039987 | CVE | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11885 | [email protected] | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44616/ | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102055 | [email protected] | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039987 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft windows 10 | 1511 1607 1703 1709 |
CPE
Remediation
| |
| microsoft windows 7 | All versions |
CPE
Remediation
| |
| microsoft windows 8.1 | All versions |
CPE
Remediation
| |
| microsoft windows rt 8.1 | All versions |
CPE
Remediation
| |
| microsoft windows server 2008 | r2 sp1 |
CPE
Remediation
| |
| microsoft windows server 2012 | r2 |
CPE
Remediation
| |
| microsoft windows server 2016 | 1709 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 26, 2019 | Modified Analysis | [email protected] |
| Oct 30, 2018 | CPE Deprecation Remap | [email protected] |
| May 16, 2018 | CVE Modified | [email protected] |
| Jan 2, 2018 | Initial Analysis | [email protected] |
| Dec 14, 2017 | CVE Modified | [email protected] |