CVE-2017-11814: Infoleak
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11765, CVE-2017-11784, and CVE-2017-11785.
Affected Software
Remediation
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running the listed affected Windows client, server, or RT releases are exposed if they have not applied the available patch. The affected systems include Windows 7 SP1 through Windows 10 version 1703 and the specified Windows Server releases.
What access does an attacker need to exploit it?
The CVSS vector indicates local access and low privileges are required. No user interaction is required, and successful exploitation can disclose information without affecting integrity or availability.
Is a patch available?
Yes. The provided remediation information states that a patch is available.