Memory leak in Microsoft products - CVE-2017-8582

 

Memory leak in Microsoft products - CVE-2017-8582

Published: July 11, 2017 / Updated: August 16, 2022


Vulnerability identifier: #VU7457
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8582
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to boundary error when processing objects in memory in HTTP.sys server application component. A remote attacker can send a specially crafted request to an application, which uses HTTP.sys component and gain access to potentially sensitive information.


Affected software

Microsoft Windows
Windows Server
Microsoft Internet Information Services (IIS)

How to mitigate CVE-2017-8582

Install updates from vendor's website.


External References

Related Security Bulletins