CVE-2017-8460Sensitive Information Exposure in Corporation Windows PDF

Severity
7.3HIGHNVD
EPSS
1.9%
top 16.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 13

Description

Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows information disclosure when a user opens a specially crafted PDF file, aka "Windows PDF Information Disclosure Vulnerability".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages3 packages

NVDmicrosoft/windows_101511, 1607, 1703+2
CVEListV5microsoft_corporation/windows_pdfWindows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rmch-2qfg-mw32: Windows PDF in Windows 82022-05-13
CVEList
CVE-2017-8460: Windows PDF in Windows 82017-06-15

📋Vendor Advisories

1
Microsoft
Windows PDF Information Disclosure Vulnerability2017-06-13
CVE-2017-8460 — Sensitive Information Exposure | cvebase