CVE-2018-8121: Medium severity Microsoft Windows 10 vulnerability
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207.
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and low privileges are required. The attack has high complexity and does not require user interaction.
What is the potential impact if exploitation succeeds?
Successful exploitation can disclose information from the affected system. The CVSS vector rates confidentiality impact as high, with no integrity or availability impact indicated.
Which systems are identified as affected?
The listed affected software is Microsoft Windows 10 and Microsoft Windows Server 2016. The description also identifies Windows 10 Servers and Windows 10.
Is a fix available?
Yes. A patch is available for this vulnerability.