CVE-2017-8494: Microsoft Windows 10

High severity, CVSS 7.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticated attacker to run a specially crafted application on a targeted system when Windows Secure Kernel Mode fails to properly handle objects in memory, aka "Windows Elevation of Privilege Vulnerability".

Affected products

  • Microsoft Windows 10: affected versions not specified; version 1511 only; version 1607 only
  • Microsoft Windows Server 2016: any version

Published 2017-06-15. Last modified 2026-06-17.