Information Disclosure Vulnerability in Microsoft Windows Products
CVE-2017-8532

6.5MEDIUM

Key Information:

Vendor
Microsoft
Status
Vendor
CVE Published:
15 June 2017

Summary

A vulnerability exists in the Windows operating systems that allows improper disclosure of memory contents through graphics processing. This issue affects various versions of Windows, including Windows Server 2008, Windows 7, Windows 8.1, and several releases of Windows 10. The improper management of graphics data may enable an attacker to access sensitive information, posing a risk to the security and integrity of affected systems. Microsoft has detailed the impact and remediation steps for this issue in an official advisory.

Affected Version(s)

Graphics Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.