#VU9310 Information disclosure in Windows and Windows Server - CVE-2017-11768
Published: November 14, 2017 / Updated: November 14, 2017
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists in Windows Media Player due to improper disclosure of file information when handling user-supplied input. A local attacker can execute an application that submits malicious input to access sensitive information on the targeted system, which could be used to conduct additional attacks.