Information disclosure in Microsoft Windows and Windows Server - CVE-2017-8462
Published: June 13, 2017 / Updated: September 14, 2018
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to improper initialization of a memory address by the Windows kernel. A local attacker can run a specially crafted application, trigger memory corruption and gain access to potentially sensitive information.
Successful exploitation of the vulnerability may result in Kernel Address Space Layout Randomization (KASLR) bypass.
Affected software
Windows Server