97462vdb entry
http://www.securityfocus.com/bid/97462 CVE-2017-0058
MEDIUM
Microsoft Windows Kernel - 'win32k.sys' Multiple 'NtGdiGetDIBitsInternal' System Call
Record summary
CVE-2017-0058 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.
Description
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | Windows | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows Kernel - 'win32k.sys' Multiple 'NtGdiGetDIBitsInternal' System CallExploitDB exploitby Google Security ResearchNot analyzed1 file
References
51038239vdb entry
http://www.securitytracker.com/id/1038239 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-0058 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0058 41879exploit
https://www.exploit-db.com/exploits/41879