#VU9649 Information disclosure in Windows and Windows Server - CVE-2017-11927
Published: December 12, 2017 / Updated: December 12, 2017
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to an error in implementation, when the Windows "its://" protocol handler unnecessarily sends traffic to a remote site in order to determine the zone of a provided URL. A remote attacker can create a specially crafted web page, trick the victim into opening it and obtain potentially sensitive information, such as NTLM hash.