Information disclosure in Microsoft Windows and Windows Server - CVE-2017-0096

 

Information disclosure in Microsoft Windows and Windows Server - CVE-2017-0096

Published: March 14, 2017


Vulnerability identifier: #VU6047
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0096
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker with access to guest operating system to disclose memory information on the host system.

The vulnerability exists due to improper input validation in Windows Hyper-V. An attacker with access to guest operating system can disclose memory information on the host operating system.

Successful exploitation of this vulnerability may allow an attacker to gain access to potentially sensitive information.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2017-0096

Install updates from vendor's website.



External References

Related Security Bulletins