CVE-2017-8575Sensitive Information Exposure in Corporation Microsoft Windows

Severity
5.5MEDIUMNVD
EPSS
2.1%
top 15.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 29
Latest updateMay 17

Description

The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application, aka "Microsoft Graphics Component Information Disclosure Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages11 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-xvp4-65m6-779w: The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specia2022-05-17

📋Vendor Advisories

3
Microsoft
Microsoft Graphics Component Information Disclosure Vulnerability2017-06-13
Red Hat
tcpdump: multiple overflow issues in protocol decoding2017-02-02
Red Hat
tcpdump: multiple overflow issues in protocol decoding2017-02-02

💬Community

1
HackerOne
CVE-2017-5482 The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print().2019-10-08
CVE-2017-8575 — Sensitive Information Exposure | cvebase