Record summary

CVE-2017-0058 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.

Description

A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability."

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListWindowsaffected

Proofs of concept

1

Catalogued exploits

ExploitDBMicrosoft Windows Kernel - 'win32k.sys' Multiple 'NtGdiGetDIBitsInternal' System CallExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details

References

5