#VU7457 Memory leak in Microsoft products - CVE-2017-8582
Published: July 11, 2017 / Updated: August 16, 2022
Windows
Windows Server
Microsoft Internet Information Services (IIS)
Microsoft
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to boundary error when processing objects in memory in HTTP.sys server application component. A remote attacker can send a specially crafted request to an application, which uses HTTP.sys component and gain access to potentially sensitive information.