Information Disclosure Vulnerability in Windows Kernel by Microsoft
CVE-2017-11842
4.7MEDIUM
Summary
This vulnerability occurs in the Windows kernel due to improper initialization of a memory address, allowing an attacker to log in and execute a specially crafted application. This exposure could lead to sensitive information being disclosed, making systems susceptible to further exploitation. Affected systems include various versions of Windows and Windows Server, underscoring the need for timely updates and patches to mitigate risks associated with this issue.
Affected Version(s)
Windows Kernel Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709.
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved