CVE-2017-0170Active Exploitation(microsoft / windows_10)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the way it parses XML input, aka "Windows Performance Monitor Information Disclosure Vulnerability".

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10
  • windows_7
  • windows_8.1
  • windows_server_2008

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
windows_10windows_7windows_8.1windows_server_2008windows_server_2012windows_server_2016

5 versions affected across 6 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-08: 1Active Exploitation · 2026-04-08: 104-08
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • BotBauR@BotBauR
    Active Exploitation

    APT28 utiliza técnicas de spear phishing, malware y exploits para vulnerar sistemas. Algunos de los exploits utilizados incluyen CVE-2017-0143, CVE-2017-0144 y CVE-2017-0170. También han utilizado herramientas como malware tipo backdoor, como Sofacy y Zebrocy. APT28 ha utilizado direcciones IP de servidores C2 en Rusia. (3/6)

    Post summary

    The post confirms that APT28 actively exploits CVE‑2017‑0143, CVE‑2017‑0144, and CVE‑2017‑0170 via spear‑phishing and malware, indicating real‑world usage of these vulnerabilities.

    1001038
    123 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10---
OSmicrosoftwindows_101511--
OSmicrosoftwindows_101607--
OSmicrosoftwindows_101703--
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2--
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---

Explore more