#VU13013 Information disclosure in Windows and Windows Server - CVE-2017-8462
Published: June 13, 2017 / Updated: September 14, 2018
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to improper initialization of a memory address by the Windows kernel. A local attacker can run a specially crafted application, trigger memory corruption and gain access to potentially sensitive information.
Successful exploitation of the vulnerability may result in Kernel Address Space Layout Randomization (KASLR) bypass.