Information Disclosure Vulnerability in Microsoft Windows HTTP.sys
CVE-2017-8582
Key Information:
What is CVE-2017-8582?
The HTTP.sys component in various versions of Microsoft Windows has a vulnerability that could allow an attacker to access sensitive information. This occurs due to the improper handling of objects in memory, which may lead to data leaks. Affected versions include Windows Server 2008 SP2, Windows 7 SP1, and several others, making it crucial for users to apply the appropriate security updates to mitigate the risk of unauthorized data exposure.
Affected Version(s)
Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 HTTP.sys
References
EPSS Score
12% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved