Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2017-0263
Microsoft Win32k
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .1003 95.5 YES
AFFECTED
Product Versions Fixed
Microsoft Windows Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 – —
TIMELINE
Sep 9 Reserved by microsoft
May 12 Published (CNA: microsoft)
Feb 10 Added to CISA KEV, remediation due 2022-08-10
Description
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 9, 2016 | Reserved | Reserved by microsoft |
| May 12, 2017 | Published | Published (CNA: microsoft) |
| February 10, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-08-10 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Microsoft Corporation | Microsoft Windows | — | Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2017-0263 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.