Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-0259Sensitive Information Exposure in Corporation Microsoft Windows

Severity
4.7MEDIUMNVD
EPSS
3.2%
top 13.02%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 12
Latest updateMay 17

Description

The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0220, and CVE-2017-0258.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages16 packages

NVDmicrosoft/windows_101511, 1607, 1703+2
CVEListV5microsoft_corporation/microsoft_windowsMicrosoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016

Patches

🔴Vulnerability Details

4
GHSA
GHSA-29j5-85v7-89h5: The Windows kernel in Microsoft Windows 82022-05-17
GHSA
GHSA-gjgh-xm4c-7q3x: The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensiti2022-05-17
GHSA
GHSA-2h8j-5vrm-5737: The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a speci2022-05-14
GHSA
GHSA-cw7v-rc9m-6mcv: The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 82022-05-13

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows 10 Kernel - 'nt!NtTraceControl (EtwpSetProviderTraits)' Pool Memory Disclosure2017-05-15

📋Vendor Advisories

1
Microsoft
Windows Kernel Information Disclosure Vulnerability2017-05-09

🕵️Threat Intelligence

4
Talos
Microsoft Patch Tuesday - May 20172017-05-10
Talos
Vulnerability Spotlight: Adobe Acrobat Reader DC jpeg Decoder Vulnerability2017-01-20
Talos
Vulnerability Spotlight: Adobe Acrobat Reader DC jpeg Decoder Vulnerability2017-01-20
Zscaler
Zscaler found Multiple Security Vulnerabilities | 05-09-2017
CVE-2017-0259 — Sensitive Information Exposure | cvebase