1.9
CVSSv2

CVE-2017-0058

Published: 12/04/2017 Updated: 16/08/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 195
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows vista

microsoft windows server 2008 r2

microsoft windows 10 1703

microsoft windows rt 8.1

microsoft windows 7

microsoft windows server 2012 r2

microsoft windows 8.1

microsoft windows 10 1511

microsoft windows 10 1607

microsoft windows server 2016

microsoft windows server 2012

microsoft windows server 2008

microsoft windows 10

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=1078 We have discovered two bugs in the implementation of the win32k!NtGdiGetDIBitsInternal system call, which is a part of the graphic subsystem in all modern versions of Windows The issues can potentially lead to kernel pool memory disclosure (bug #1) or denial of service (bug #1 ...