Information Disclosure Vulnerability in Microsoft Windows HTTP.sys
CVE-2017-8582

5.9MEDIUM

Summary

The HTTP.sys component in various versions of Microsoft Windows has a vulnerability that could allow an attacker to access sensitive information. This occurs due to the improper handling of objects in memory, which may lead to data leaks. Affected versions include Windows Server 2008 SP2, Windows 7 SP1, and several others, making it crucial for users to apply the appropriate security updates to mitigate the risk of unauthorized data exposure.

Affected Version(s)

Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 HTTP.sys

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.