Windows DirectShow Information Disclosure Vulnerability



Published: 2017-04-11
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2017-0042
CWE-ID CWE-200
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Windows
Operating systems & Components / Operating system

Windows Server
Operating systems & Components / Operating system

Vendor Microsoft

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU5954

Risk: Low

CVSSv3.1: 3.1 [CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-0042

CWE-ID: CWE-200 - Information Exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to improper handling of objects in memory by Windows DirectShow. A remote unauthenticated attacker can create a Web site containing a specially crafted content, trick the victim into visiting it and gain access to important data.

Successful exploitation of this vulnerability results in information disclosure.

Mitigation

Install updates from Microsoft website.

Vulnerable software versions

Windows: 7, 10, RT, RT 8.1, Vista

Windows Server: 2008, 2008 R2, 2012, 2012 R2, 2016

CPE2.3 External links

http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0042

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###