PT-2017-12273 · Microsoft · Windows Server 2012 R2+6
Published
2017-11-14
·
Updated
2022-05-23
·
CVE-2017-11850
CVSS v3.1
2.5
Low
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows 8.1 and RT 8.1
Windows Server 2012 and R2
Windows 10 versions 1511 through 1709
Windows Server 2016 and Windows Server, version 1709
Description
The issue is related to improper handling of objects in memory, allowing an attacker to run a specially crafted application on an affected system. This can potentially lead to sensitive information disclosure.
Recommendations
For Windows 8.1 and RT 8.1, update to a newer version to mitigate the risk.
For Windows Server 2012 and R2, apply the recommended security updates.
For Windows 10 versions 1511 through 1709, install the latest cumulative update.
For Windows Server 2016 and Windows Server, version 1709, apply the necessary patches.
As a temporary workaround, consider restricting access to sensitive system resources until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10
Windows 8.1
Windows Rt 8.1
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016