Information Disclosure Vulnerability in Microsoft Windows Hyper-V
CVE-2017-8706

5.3MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
13 September 2017

Summary

The Windows Hyper-V component on various versions of Microsoft Windows facilitates an abuse of input validation, leading to potential information disclosure from a guest operating system. This vulnerability arises from inadequate checks performed on inputs from authenticated users, which could allow attackers to expose sensitive information within the host system. Mitigation measures are essential to protect against unauthorized data access in virtualized environments.

Affected Version(s)

Windows Hyper-V Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.