CVE-2017-8582: Infoleak
HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when the component improperly handles objects in memory, aka "Https.sys Information Disclosure Vulnerability".
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems are affected?
Affected systems include Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and 2012 R2, Windows RT 8.1, Windows 10 Gold through version 1703, and Windows Server 2016.
What access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed over the network without privileges or user interaction. It also indicates high attack complexity.
What is the security impact?
The vulnerability is an information disclosure issue caused by improper handling of objects in memory by HTTP.sys. The supplied CVSS vector rates confidentiality impact as high, with no integrity or availability impact.
Is a fix available?
Yes. A patch is available.