CVE-2017-8566: Microsoft Windows 10

High severity, CVSS 7.0. EPSS: 1% chance of exploitation in the next 30 days.

Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improperly handling parameters in a method of a DCOM class, aka "Windows IME Elevation of Privilege Vulnerability".

Affected products

  • Microsoft Windows 10: version 1607 only; version 1703 only
  • Microsoft Windows Server 2016: any version

Published 2017-07-11. Last modified 2026-06-17.