CVE-2017-11849: Infoleak
Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing a memory address, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11842, CVE-2017-11851, and CVE-2017-11853.
Affected Software
Remediation
Event History
Frequently Asked Questions
What access does an attacker need to exploit this vulnerability?
The attacker must be able to log on to an affected Windows system and run a specially crafted application. The CVSS vector also indicates local access, low privileges, and no user interaction are required.
What is the likely impact if exploitation succeeds?
Successful exploitation can disclose information because the Windows kernel improperly initializes a memory address. The supplied CVSS vector indicates high confidentiality impact, with no integrity or availability impact.
Which systems are affected?
Affected systems include listed releases of Windows 7 SP1, Windows 8.1 and RT 8.1, Windows 10 through version 1709, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows Server 2016, and Windows Server version 1709.
Is a fix available?
Yes. A patch is available for this vulnerability.