PT-2018-1797 · Microsoft · Windows Server 2012 R2+7

Scott Bell

·

Published

2018-11-13

·

Updated

2020-08-24

·

CVE-2018-8563

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows 7 Windows Server 2012 R2 Windows RT 8.1 Windows Server 2012 Windows 8.1 Windows Server 2008 R2
Description The issue is related to improper handling of objects in memory by DirectX, which can lead to information disclosure. This can be exploited by an attacker using a specially crafted application to reveal protected information.
Recommendations For Windows 7, update to a newer version that includes the fix for this issue. For Windows Server 2012 R2, apply the necessary patch to resolve the vulnerability. For Windows RT 8.1, Windows Server 2012, Windows 8.1, and Windows Server 2008 R2, ensure that all security updates are installed to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to sensitive information until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01397
CVE-2018-8563

Affected Products

Directx
Windows
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2