Windows Kernel Vulnerability in Multiple Windows Versions
CVE-2017-11853

5.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
15 November 2017

Summary

A vulnerability in the Windows kernel could allow an attacker to log in and execute a specially crafted application due to improper initialization of a memory address. This weakness affects several versions of Windows, posing security risks by potentially exposing sensitive information.

Affected Version(s)

Windows kernel Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709.

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.