PT-2017-10435 · Microsoft · Windows Server 2012 R2+5

Published

2017-04-11

·

Updated

2017-08-16

·

CVE-2017-0167

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows 8.1 Windows RT 8.1 Windows Server 2012 R2 Windows 10 Windows Server 2016
Description The issue arises from the Windows kernel's improper handling of objects in memory, allowing an attacker to obtain information that could be used to further compromise the system. This could potentially lead to sensitive information disclosure and affect the system.
Recommendations For Windows 8.1, update to a version that properly handles objects in memory to prevent information disclosure. For Windows RT 8.1, apply the necessary patches to fix the kernel's handling of memory objects. For Windows Server 2012 R2, Windows 10, and Windows Server 2016, ensure that the Windows kernel is updated to a version that correctly manages memory objects to mitigate the risk of information disclosure.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0167

Affected Products

Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012 R2
Windows Server 2016