peter bassill · operator
$ cve CVE-2017-0259 JSON

CVE-2017-0259 EXPLOIT

4.7
MEDIUM · CVSS 3.0 · EPSS 9.7% (pctl 95)

Patch early

A public exploit exists.

Description

The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0220, and CVE-2017-0258.

Scoring

CVSS4.7 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS9.66% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2017-05-12
Last modified2026-06-17

Affected (5)

VendorProduct
microsoftwindows 10
microsoftwindows 8.1
microsoftwindows rt 8.1
microsoftwindows server 2012
microsoftwindows server 2016

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD