Information disclosure in Windows and Windows Server - CVE-2017-0096

 

Information disclosure in Windows and Windows Server - CVE-2017-0096

Published: March 14, 2017


Vulnerability identifier: #VU6047
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-0096
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Windows
Windows Server

Detailed vulnerability description

The vulnerability allows a remote attacker with access to guest operating system to disclose memory information on the host system.

The vulnerability exists due to improper input validation in Windows Hyper-V. An attacker with access to guest operating system can disclose memory information on the host operating system.

Successful exploitation of this vulnerability may allow an attacker to gain access to potentially sensitive information.


How to mitigate CVE-2017-0096

Install updates from vendor's website.


Sources