PT-2018-1797 · Microsoft · Windows Server 2012 R2+7
Scott Bell
·
Published
2018-11-13
·
Updated
2020-08-24
·
CVE-2018-8563
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows 7
Windows Server 2012 R2
Windows RT 8.1
Windows Server 2012
Windows 8.1
Windows Server 2008 R2
Description
The issue is related to improper handling of objects in memory by DirectX, which can lead to information disclosure. This can be exploited by an attacker using a specially crafted application to reveal protected information.
Recommendations
For Windows 7, update to a newer version that includes the fix for this issue.
For Windows Server 2012 R2, apply the necessary patch to resolve the vulnerability.
For Windows RT 8.1, Windows Server 2012, Windows 8.1, and Windows Server 2008 R2, ensure that all security updates are installed to mitigate the risk of exploitation.
As a temporary workaround, consider restricting access to sensitive information until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directx
Windows
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2