#VU8304 Information disclosure in Windows and Windows Server - CVE-2017-8688
Published: September 12, 2017 / Updated: September 12, 2017
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to improper handling objects in memory by the Windows Graphics Device Interface+ (GDI+). A local attacker can run a specially crafted application and retrieve arbitrary data on the target system.