Information Disclosure Vulnerability in Microsoft Windows Kernel
CVE-2018-0811

5.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 March 2018

Summary

The Windows kernel in various versions of Microsoft Windows contains a vulnerability allowing unauthorized access to sensitive information. This occurs due to improper handling of object initialization in memory, which can be exploited to reveal confidential data. Affected systems include multiple iterations of Windows Server and client operating systems, underscoring the importance for users and administrators to implement security updates promptly.

Affected Version(s)

Windows kernel Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.