Information disclosure in Microsoft Windows and Windows Server - CVE-2017-11768

 

Information disclosure in Microsoft Windows and Windows Server - CVE-2017-11768

Published: November 14, 2017 / Updated: November 14, 2017


Vulnerability identifier: #VU9310
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11768
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists in Windows Media Player due to improper disclosure of file information when handling user-supplied input. A local attacker can execute an application that submits malicious input to access sensitive information on the targeted system, which could be used to conduct additional attacks.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2017-11768

Install update from vendor's website.


External References

Related Security Bulletins