4.7
CVSSv3

CVE-2017-0220

Published: 12/05/2017 Updated: 13/08/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 195
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated malicious users to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0258, and CVE-2017-0259.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 7

microsoft windows server 2008 r2

microsoft windows server 2012 -

microsoft windows server 2008

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=1127 We have identified two related bugs in Windows kernel code responsible for implementing the bind() socket function, specifically in the afd!AfdBind and tcpip!TcpBindEndpoint routines They both can lead to reading beyond the allocated pool-based buffer memory area, potentially ...