Information disclosure in Microsoft Windows and Windows Server - CVE-2017-11927
Published: December 12, 2017 / Updated: December 12, 2017
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in implementation, when the Windows "its://" protocol handler unnecessarily sends traffic to a remote site in order to determine the zone of a provided URL. A remote attacker can create a specially crafted web page, trick the victim into opening it and obtain potentially sensitive information, such as NTLM hash.
Affected software
Windows Server