Information Disclosure Vulnerability in Microsoft Hyper-V on Windows Products
CVE-2017-8713

5.3MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
13 September 2017

Summary

The Hyper-V component in various Microsoft Windows editions contains an information disclosure vulnerability due to inadequate input validation from authenticated users within guest operating systems. This flaw exposes sensitive information, potentially allowing unauthorized access to data not intended for the user. Multiple versions of Windows, including Windows 8.1, various server iterations, and multiple Windows 10 updates are affected, highlighting the importance of securing these environments.

Affected Version(s)

Windows Hyper-V Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.