PT-2017-10435 · Microsoft · Windows Server 2012 R2+5
Published
2017-04-11
·
Updated
2017-08-16
·
CVE-2017-0167
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows 8.1
Windows RT 8.1
Windows Server 2012 R2
Windows 10
Windows Server 2016
Description
The issue arises from the Windows kernel's improper handling of objects in memory, allowing an attacker to obtain information that could be used to further compromise the system. This could potentially lead to sensitive information disclosure and affect the system.
Recommendations
For Windows 8.1, update to a version that properly handles objects in memory to prevent information disclosure.
For Windows RT 8.1, apply the necessary patches to fix the kernel's handling of memory objects.
For Windows Server 2012 R2, Windows 10, and Windows Server 2016, ensure that the Windows kernel is updated to a version that correctly manages memory objects to mitigate the risk of information disclosure.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012 R2
Windows Server 2016