CVE-2017-8713
published 2017-09-13CVE-2017-8713: The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016…
PriorityP424medium5.3CVSS 3.0
AVLACHPRHUINSCCHINAN
EPSS
3.48%
87.8th percentile
The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8706.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | windows_hyper-v | — | — |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
vendor_msrc7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pgrg-8fhr-7vx5: The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabili
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8706 [MEDIUM] CWE-200 GHSA-pgrg-8fhr-7vx5: The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabili
The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.
GHSA
GHSA-4j97-wvjp-h3gq: The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8707 [MEDIUM] CWE-200 GHSA-4j97-wvjp-h3gq: The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8
The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8706, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.
GHSA
GHSA-h3g9-rw58-vgq2: The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to pro
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8711 [MEDIUM] CWE-200 GHSA-h3g9-rw58-vgq2: The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to pro
The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8706, CVE-2017-8712, and CVE-2017-8713.
GHSA
GHSA-6chf-jwrr-c4pv: The Windows Hyper-V component on Microsoft Windows Windows 8
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8713 [MEDIUM] CWE-200 GHSA-6chf-jwrr-c4pv: The Windows Hyper-V component on Microsoft Windows Windows 8
The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8706.
GHSA
GHSA-jpwm-6fvr-35jv: The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails
ghsa_unreviewed·2022-05-17·CVSS 5.3
CVE-2017-8712 [MEDIUM] CWE-200 GHSA-jpwm-6fvr-35jv: The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails
The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8706, and CVE-2017-8713.
Red Hat
postgresql: PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
vendor_redhat·2025-08-14·CVSS 7.5
CVE-2025-8713 [HIGH] CWE-1230 postgresql: PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
postgresql: PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of
Microsoft
Windows Hyper-V Information Disclosure Vulnerability
vendor_msrc·2017-09-12·CVSS 7.2
CVE-2017-8713 [MEDIUM] Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disclose memory information.
An attacker who successfully exploited the vulnerability could gain access to information on the Hyper-V host operating system.
The security update addresses the vulnerability by correcting how Hyper-V validates guest operating system user input.
Windows Hyper-V: Windows Hyper-V
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Ex
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/100796http://www.securitytracker.com/id/1039317https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8713http://www.securityfocus.com/bid/100796http://www.securitytracker.com/id/1039317https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8713
2017-09-13
Published