98854vdb entry
http://www.securityfocus.com/bid/98854 CVE-2017-8477
MEDIUM
Microsoft Windows - 'win32k!NtGdiMakeFontDir' Kernel Stack Memory Disclosure
Record summary
CVE-2017-8477 has a selected CVSS score of 5.0 (medium); EIP currently links 1 catalogued exploit.
Description
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8470, CVE-2017-8471, CVE-2017-8472, CVE-2017-8473, CVE-2017-8475, and CVE-2017-8484.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Microsoft WindowsBrowse Microsoft Corporation / Microsoft Windows | CVE List | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016. | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows - 'win32k!NtGdiMakeFontDir' Kernel Stack Memory DisclosureExploitDB exploitby Google Security ResearchNot analyzed1 file
References
51038659vdb entry
http://www.securitytracker.com/id/1038659 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-8477 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8477 42230exploit
https://www.exploit-db.com/exploits/42230