CVE-2017-0175
MEDIUMWindows 7 SP1 and Windows Server 2008 SP2/R2 SP1 - Authenticated Information Disclosure via Crafted Document
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0175. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit demonstrates a double-fetch vulnerability in the Windows kernel's `afd!AfdBind` function, leading to potential information disclosure or denial of service (DoS) via a race condition. The PoC targets Windows 7 32-bit systems by manipulating the input structure during the `bind()` socket operation.
Description
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0220, CVE-2017-0258, and CVE-2017-0259.
Exploits (1)
The exploit demonstrates a double-fetch vulnerability in the Windows kernel's `afd!AfdBind` function, leading to potential information disclosure or denial of service (DoS) via a race condition. The PoC targets Windows 7 32-bit systems by manipulating the input structure during the `bind()` socket operation.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N