Information Disclosure Vulnerability in Windows Products by Microsoft
CVE-2017-8666
5.5MEDIUM
Summary
The vulnerability in Microsoft Win32k allows an attacker to access sensitive information that could be stored in memory. This could potentially enable an unauthorized disclosure of protected information, compromising system security. The flaw affects various versions of the Windows operating system, including legacy systems. Proper remediation is necessary to mitigate the risks associated with this information disclosure vulnerability.
Affected Version(s)
Windows Kernel-Mode Drivers Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved