Information disclosure in Windows and Windows Server - CVE-2017-0057
Published: March 14, 2017 / Updated: March 14, 2017
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error in Windows dnsclient when processing DNS requests. A remote unauthenticated attacker can create a specially crafted web page, trick the victim into visiting it and force the client to connect to a malicious DNS server.
Successful exploitation of this vulnerability may allow an attacker to gain access to potentially sensitive information.
How to mitigate CVE-2017-0057
Install updates from vendor's website.